漏洞描述
The W3 Total Cache WordPress plugin before 2.1.4 was vulnerable to a reflected Cross-Site Scripting (XSS) security vulnerability within the "extension" parameter in the Extensions dashboard, which is output in an attribute without being escaped first. This could allow an attacker, who can convince an authenticated admin into clicking a link, to run malicious JavaScript within the user's web browser, which could lead to full site compromise.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
wpscan.comhttps://wpscan.com/vulnerability/3e855e09-056f-45b5-89a9-d644b7d8c9d0↗wordpress.orghttps://wordpress.org/plugins/w3-total-cache/↗wpscan.comhttps://wpscan.com/vulnerability/05988ebb-7378-4a3a-9d2d-30f8f58fe9ef↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2021-24436↗github.comhttps://github.com/ARPSyndicate/cvemon↗