漏洞描述
Easy Social Feed < 6.2.7 is susceptible to reflected cross-site scripting because the plugin does not sanitize and escape a parameter before outputting it back in an admin dashboard page, leading to it being executed in the context of a logged admin or editor.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
wpscan.comhttps://wpscan.com/vulnerability/6dd00198-ef9b-4913-9494-e08a95e7f9a0↗wpscan.comhttps://wpscan.com/vulnerability/0ad020b5-0d16-4521-8ea7-39cd206ab9f6↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2021-25120↗github.comhttps://github.com/ARPSyndicate/cvemon↗github.comhttps://github.com/ARPSyndicate/kenzer-templates↗