Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Patreon WordPress < 1.7.0 - CSRF to Overwrite/Create User Meta
Vulnerability Description
The Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon WordPress plugin before 1.7.0, allowing attackers to make a logged in user overwrite or create arbitrary user metadata on the victim’s account once visited. If exploited, this bug can be used to overwrite the “wp_capabilities” meta, which contains the affected user account’s roles and privileges. Doing this would essentially lock them out of the site, blocking them from accessing paid content.
CVSS Information
N/A
Vulnerability Type
跨站请求伪造(CSRF)
Vulnerability Title
WordPress 插件 跨站请求伪造漏洞
Vulnerability Description
WordPress 插件是WordPress开源的一个应用插件。 WordPress 插件 Patreon 1.7.0版本之前存在跨站请求伪造漏洞,该漏洞会使攻击者在登录用户访问时覆盖或在受害者的帐户上创建任意用户元数据。
CVSS Information
N/A
Vulnerability Type
N/A