[CVE-2026-14835] The SOGO Add Script to Individual Pages Header Footer WordPr

CVE-2026-14835 | CVSS: N/A

The SOGO Add Script to Individual Pages Header Footer WordPress plugin through 3.9 does not sanitise or escape the custom header/footer script values saved from its post metabox, and does not restrict them to users with the unfiltered_html capability, allowing users with contributor-level access and above to store JavaScript that executes in the browser of any administrator who reviews the post and of any visitor once the post is published.

参考链接:
https://wpscan.com/vulnerability/f0b869b1-ef43-4540-9ca5-4440e763d307/

📌 数据来源: NVD 官方

⚠️ 合规声明: 本文内容仅用于网络安全合规学习、科研与授权测试用途。严禁用于任何未授权行为,违者自行承担全部法律责任。
滚动至顶部