Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | WordPress Tutor LMS plugin before 2.0.10 contains a cross-site scripting vulnerability. The plugin does not sanitize and escape the reset_key and user_id parameters before outputting then back in attributes. An attacker can inject arbitrary script in the browser of an unsuspecting user in the context of the affected site, which can allow the attacker to steal cookie-based authentication credentials and launch other attacks. This vulnerability can be used against high-privilege users such as admin. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-0236.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2022-4838 | Clean Login < 1.13.7 - Contributor+ Stored XSS via Shortcode | |
| CVE-2022-4384 | Stream < 3.9.2 - Subscriber+ Alert Creation | |
| CVE-2022-4717 | Strong Testimonials < 3.0.3 - Contributor+ Stored XSS via Shortcode | |
| CVE-2023-0070 | ResponsiveVoice Text To Speech < 1.7.7 - Contributor+ Stored XSS | |
| CVE-2023-0154 | GamiPress – Vimeo integration < 1.0.9 - Contributor+ Stored XSS | |
| CVE-2022-4824 | WP Blog and Widget < 2.3.1 - Contributor+ Stored XSS via Shortcode | |
| CVE-2022-4577 | Easy Testimonials < 3.9.3 - Contributor+ Stored XSS | |
| CVE-2023-0178 | Annual Archive < 1.6.0 - Contributor+ Stored XSS | |
| CVE-2022-4664 | Logo Slider < 3.6.0 - Contributor+ Stored XSS in Shortcode | |
| CVE-2022-4833 | YourChannel: Everything you want in a YouTube plugin < 1.2.3 - Contributor+ Stored XSS via | |
| CVE-2022-4825 | WP-ShowHide < 1.05 - Contributor+ Stored XSS via Shortcode | |
| CVE-2022-4681 | Hide My WP < 6.2.9 - Unauthenticated SQLi | |
| CVE-2023-0148 | Gallery Factory Lite <= 2.0.0 - Contributor+ Stored XSS | |
| CVE-2023-0095 | Page View Count < 2.6.1 - Contributor+ Stored XSS | |
| CVE-2022-4674 | Ibtana – WordPress Website Builder < 1.1.8.8 - Contributor+ Stored XSS via Shortcode | |
| CVE-2023-0282 | YourChannel < 1.2.2 - Subscriber+ Stored XSS | |
| CVE-2022-4459 | WP Show Posts < 1.1.4 - Contributor+ Stored XSS | |
| CVE-2023-0144 | Event Manager and Tickets Selling Plugin for WooCommerce < 3.8.0 - Contributor+ Stored XSS | |
| CVE-2022-4321 | PDF Generator for WordPress < 1.1.2 - Reflected XSS | |
| CVE-2023-0153 | Vimeo Video Autoplay Automute <= 1.0 - Contributor+ Stored XSS |
Showing top 20 of 48 CVEs. View all on vendor page → →
No comments yet