WordPress 插件 WP Statistics(一种简单且注重隐私的 Google Analytics 替代方案)存在反射型跨站脚本漏洞(Reflected Cross-Site Scripting,简称 XSS)。该漏洞出现在所有不超过 14.16.14 版本的插件中,原因是插件对用户输入缺乏足够的 sanitization(清理)和 output escaping(输出转义),具体表现为 REQUEST_URI 查询参数键值未正确处理。 攻击者可以构造恶意链接,诱使已登录用户点击,从而在用户浏览器中执行任
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| veronalabs | WP Statistics – Simple, privacy-friendly Google Analytics alternative | 0 ~ 14.16.14 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet