标题:WordPress plugin Ocean Extra 跨站脚本漏洞
(CVE-2021-25104) Description:WordPress和WordPress plugin都是WordPress基金会的产品。WordPress是一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。WordPress plugin是一个应用插件。 WordPress plugin Ocean Extra 1.9.5之前版本存在跨站脚本漏洞,该漏洞源于不会转义生成的链接。
Description
WordPress Ocean Extra plugin before 1.9.5 contains a cross-site scripting vulnerability. The plugin does not escape generated links which are then used when the OceanWP theme is active.