WordPress 插件 AccessPress Social Icons 1.8.2 存储型跨站脚本 (XSS) 漏洞 漏洞概述 漏洞类型:存储型跨站脚本 (Stored XSS) 漏洞组件:WordPress 插件 AccessPress Social Icons 触发点: 字段 EDB-ID:50615 发布日期:2021-11-12 作者:Murat DEMIRCI 影响范围 受影响软件:AccessPress Social Icons 受影响版本:1.8.2 运行环境:PHP 平台,测试环境为 Windows 10 修复方案 目前页面未提供具体的补丁链接或修复代码。 建议用户升级至非 1.8.2 版本或联系厂商获取更新。 POC 代码 ```text Exploit Title: WordPress Plugin AccessPress Social Icons 1.8.2 - 'icon title' Stored Cross-Site Scripting (XSS) Date: 11/12/2021 Exploit Author: Murat DEMIRCI (@butterflyhunt3r) Vendor Homepage: https://accesspressthemes.com/ Software Link: https://wordpress.org/plugins/accesspress-social-icons/ Version: 1.8.2 Tested on : Windows 10 #PoC: 1. Install Latest WordPress 2. Install and activate AccessPress Social Icons 1.8.2 3. Open plugin on the left frame and keep going "add new" field. Click "Choose icon individually" and fill other fields.