Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
LabTools <= 1.0 - Subscriber+ Arbitrary Publication Deletion
Vulnerability Description
The LabTools WordPress plugin through 1.0 does not have proper authorisation and CSRF check in place when deleting publications, allowing any authenticated users, such as subscriber to delete arbitrary publication
CVSS Information
N/A
Vulnerability Type
跨站请求伪造(CSRF)
Vulnerability Title
WordPress 安全漏洞
Vulnerability Description
WordPress plugin是WordPress开源的一个应用插件。 WordPress plugin LabTools 1.0及之前版本存在安全漏洞,该漏洞源于在删除发布时没有适当的授权,允许任何经过身份验证的用户(如订阅者)删除任意发布。
CVSS Information
N/A
Vulnerability Type
N/A