漏洞分析
在文件 WordPress/wp-admin/load-scripts.php 中:
<?php
......该JS文件白名单的内容在文件 WordPress/wp-includes/script-loader.php 中:
......', 'jquery-color' ), false, 1 );
// WordPress no longer uses or bundles Prototype or script.aculo.us...media-editor,media-audiovideo,mce-view,wp-api,admin-tags,admin-comments,xfn,postbox,tags-box,tags-suggest,post...media-image-widget,media-gallery-widget,media-video-widget,text-widgets,custom-html-widgets,theme,inline-edit-post