Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2022-3506 PoC — related-posts-for-wp 跨站脚本漏洞

Source
Associated Vulnerability
Title:related-posts-for-wp 跨站脚本漏洞 (CVE-2022-3506)
Description:related-posts-for-wp是Barry Kooij个人开发者的一个库。用于只需单击一次即可将 WordPress 相关帖子相互链接。 related-posts-for-wp 2.1.3之前版本存在跨站脚本漏洞。攻击者利用该漏洞执行跨站脚本攻击。
Description
WordPress Related Posts plugin prior to 2.1.3 contains a cross-site scripting vulnerability in the rp4wp[heading_text] parameter. User input is not properly sanitized, allowing the insertion of arbitrary code that  can allow an attacker to steal cookie-based authentication credentials and launch other attacks.
File Snapshot

id: CVE-2022-3506 info: name: WordPress Related Posts <2.1.3 - Stored Cross-Site Scripting auth ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.