漏洞描述
WordPress WP-Ban plugin before 1.69.1 contains a stored cross-site scripting vulnerability. The plugin does not sanitize and escape some of its settings, which can allow high-privilege users to steal cookie-based authentication credentials and launch other attacks. This vulnerability can be exploited even when the unfiltered_html capability is disallowed, for example in multisite setup.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
wpscan.comhttps://wpscan.com/vulnerability/d0cf24be-df87-4e1f-aae7-e9684c88e7db↗cve.mitre.orghttps://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-4260↗drive.google.comhttps://drive.google.com/file/d/11nQ21cQ9irajYqNqsQtNrLJOkeRcwCXn/view?usp=drivesdk↗github.comhttps://github.com/ARPSyndicate/kenzer-templates↗