WordPress 插件 JetFormBuilder — Dynamic Blocks Form Builder 存在存储型跨站脚本(XSS)漏洞。该漏洞存在于所有 3.6.5.4 及以下版本,根源在于输入清理和输出转义处理不足。攻击者可通过“choice”字段对应的文章元数据(Post Meta),在用户访问被注入脚本的页面时执行任意 Web 脚本。 具体来说,未认证的攻击者可以通过未授权访问的 wp_ajax_nopriv_jet_form_builder_submit 端点提交恶意载荷。这些载荷在通过“插入
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| jetmonsters | JetFormBuilder — Dynamic Blocks Form Builder | ≤ 3.6.5.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| jetmonsters | JetFormBuilder — Dynamic Blocks Form Builder | 0 ~ 3.6.5.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet