该仓库涉及 Wordpress Foogallery 插件中的 XSS 漏洞。
在 Foogallery 2.2.35 及更早版本中,foogallery/includes/admin/class-gallery-attachment-modal.php 中的 foogallery_image_editor_modal 函数容易受到 XSS 攻击。
http://localhost:8080/wp-admin/post-new.php?post_type=foogallery&post=”><script>alert(1)</script>