WordPress 捐赠插件和筹款平台插件 GiveWP – Donation Plugin and Fundraising Platform 在 4.17.0 及更早版本中存在存储型跨站脚本(Stored Cross-Site Scripting, XSS)漏洞。该漏洞源于 函数对用户提供的短代码属性( 、 、 、 )缺乏足够的输入过滤和输出转义处理。此外,渲染模板在单引号包裹的 HTML 属性中直接输出 ,而未使用 进行转义。由于 默认不转义单引号,因此当属性值中包含单引号 时,即可突破其所属的 HTML 属性
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| stellarwp | GiveWP – Donation Plugin and Fundraising Platform | ≤ 4.17.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| stellarwp | GiveWP – Donation Plugin and Fundraising Platform | 0 ~ 4.17.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet