Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Tab - Accordion, FAQ < 1.3.2 - Unauthenticated AJAX Calls
Vulnerability Description
All AJAX actions of the Tab WordPress plugin before 1.3.2 are available to both unauthenticated and authenticated users, allowing unauthenticated attackers to modify various data in the plugin, such as add/edit/delete arbitrary tabs.
CVSS Information
N/A
Vulnerability Type
授权机制缺失
Vulnerability Title
WordPress 安全漏洞
Vulnerability Description
WordPress是Wordpress基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。WordPress plugin是WordPress开源的一个应用插件。 WordPress 的Tab插件 1.3.2之前版本存在安全漏洞,攻击者可利用该漏洞修改插件中的各种数据,例如添加/编辑/删除任意选项卡。
CVSS Information
N/A
Vulnerability Type
N/A