WordPress 的 Wp Social Login 和 Register Social Counter 插件在所有 3.2.1 及以下版本中存在存储型跨站脚本攻击(Stored Cross-Site Scripting, XSS)漏洞,该漏洞可通过 Avatar Alt 属性中的任意用户元数据写入实现。此问题的根本原因是输入清理和输出转义机制不足。 受此漏洞影响,拥有订阅者(Subscriber)及以上权限的攻击者可以注入任意 Web 脚本,当其他用户访问被注入脚本的页面时,这些脚本将自动执行。攻击者需要分两步
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| roxnor | Wp Social Login and Register Social Counter | 0 ~ 3.2.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100157 | 6.5 MEDIUM | WP Ultimate Review <= 2.4.3 - Unauthenticated Arbitrary Shortcode Execution via 'xs_reviw_ |
| CVE-2026-103519 | 5.4 MEDIUM | WP Ultimate Review <= 2.4.3 - Authenticated (Subscriber+) Arbitrary Shortcode Execution vi |
No comments yet