The WC Product Table Lite plugin for WordPress is vulnerable to CSS Injection in versions up to, and including, 5.6.0 via the 'laptop_scroll_offset' shortcode attribute exposed through the unauthenti…
中危 CVSS 5.3
摘要
The WC Product Table Lite plugin for WordPress is vulnerable to CSS Injection in versions up to, and including, 5.6.0 via the 'laptop_scroll_offset' shortcode attribute exposed through the unauthenticated wcpt_ajax() AJAX handler. The handler is registered for wp_ajax_nopriv_wcpt_ajax, JSON-decodes attacker-supplied attributes, only allowlists key names (not values), applies a preg_replace that strips only [ ] < >, and passes the value through do_shortcode into wcpt_style__sticky_sidebar(), whe…
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
数据来源
- NVD DATABASE
原始链接
- https://plugins.trac.wordpress.org/browser/wc-product-table-lite/tags/5.1.0/main.php#L2677
- https://plugins.trac.wordpress.org/browser/wc-product-table-lite/tags/5.1.0/main.php#L2686
- https://plugins.trac.wordpress.org/browser/wc-product-table-lite/tags/5.1.0/style-functions.php#L995
- https://plugins.trac.wordpress.org/browser/wc-product-table-lite/tags/5.4.0/main.php#L2677
- https://plugins.trac.wordpress.org/browser/wc-product-table-lite/tags/5.4.0/main.php#L2686
- https://plugins.trac.wordpress.org/browser/wc-product-table-lite/tags/5.4.0/style-functions.php#L995
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3638932%40wc-product-table-lite&new=3638932%40wc-product-table-lite
- https://www.wordfence.com/threat-intel/vulnerabilities/id/6c0a8be1-8853-4863-90e5-af3831f800e9?source=cve
时间线
- nvd_ingest NVD