Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | The Ditty WordPress plugin before 3.1.25 does not sanitise and escape some parameters and generated URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-4148.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2023-4490 | WP Job Portal < 2.0.6 - Unauthenticated SQLi | |
| CVE-2023-4300 | Import XML and RSS Feeds < 2.1.4 - Admin+ Arbitrary File Upload | |
| CVE-2023-3226 | Popup Builder < 4.2.0 - Admin+ Stored Cross-Site Scripting | |
| CVE-2023-4281 | Activity Log < 2.8.8 - IP Spoofing | |
| CVE-2023-4238 | Prevent files / folders access < 2.5.2 - Admin+ Arbitrary File Upload | |
| CVE-2023-4631 | DoLogin Security < 3.7 - IP Spoofing | |
| CVE-2023-4521 | Import XML and RSS Feeds < 2.1.5 - Unauthenticated RCE | |
| CVE-2023-4502 | Translate WordPress with GTranslate < 3.0.4 - Admin+ Stored XSS | |
| CVE-2023-4549 | DoLogin Security < 3.7 - Unauthenticated Stored Cross-Site Scripting | |
| CVE-2023-3664 | FileOrganizer <= 1.0.2 - Admin+ Arbitrary File Access | |
| CVE-2023-3547 | All in One B2B for WooCommerce <= 1.0.3 - Multiple CSRF | |
| CVE-2023-4476 | Locatoraid Store Locator < 3.9.24 - Reflected XSS |
No comments yet