WordPress是WordPress(Wordpress)基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。wpDataTables是使用在其中的一个图表管理插件。 WordPress插件 WpDataTables – Tables & Table Charts premium 3.4.2版本之前存在SQL注入漏洞,该漏洞允许低权限认证的用户在端点wp-admin admin-ajax.php的表列表页面执行基于布尔的SQL盲注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wpDataTables | wpDataTables – Tables & Table Charts | 3.4.2 ~ 3.4.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-24197 | wpDataTables < 3.4.2 - Improper Access Control leading to Table Permission Takeover | |
| CVE-2021-24198 | wpDataTables < 3.4.2 - Improper Access Control leading to Table Data Deletion | |
| CVE-2021-24200 | wpDataTables < 3.4.2 - Blind SQL Injection via length Parameter |
No comments yet