HackTips.

页面数据均来自于CVE官方,仅调用Api进行查询

1@1042.net

CVE编号CVE-2025-2078
发布日期2025-03-12T03:21:28.175Z
更新日期2025-03-12T13:26:14.638Z
状态PUBLISHED
受影响的供应商gpenverne
受影响的产品BlogBuzzTime for WP
描述The BlogBuzzTime for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

参考链接:

Image Additional Image