Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-11930 PoC — WordPress Gtranslate 跨站脚本漏洞

Source
Associated Vulnerability
Title:WordPress Gtranslate 跨站脚本漏洞 (CVE-2020-11930)
Description:WordPress是WordPress基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。 WordPress Gtranslate 2.8.52之前版本中存在跨站脚本漏洞,该漏洞源于程序没有对用户提供数据进行充足的清理。远程攻击者可借助特制链接利用该漏洞执行任意HTML和脚本。
Description
WordPress GTranslate plugin before 2.8.52 contains an unauthenticated reflected cross-site scripting vulnerability via a crafted link. This requires use of the hreflang tags feature within a sub-domain or sub-directory paid option.
File Snapshot

id: CVE-2020-11930 info: name: WordPress GTranslate <2.8.52 - Cross-Site Scripting author: dhiy ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.