WordPress是WordPress(Wordpress)基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。 WordPress plugin WordPress Popular Posts 存在代码问题漏洞,该漏洞源于 ~/src/Image.php 文件中的输入文件类型验证不足。这使得具有贡献者级别及以上访问权限的攻击者可以通过上传可以使用的恶意文件来进行远程代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| WordPress Popular Posts | WordPress Popular Posts | 0.0 ~ 5.3.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Wordpress Most Popular Post plugin vuln | https://github.com/simonecris/CVE-2021-42362-PoC | POC Details |
| 2 | The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/src/Image.php file which makes it possible for attackers with contributor level access and above to upload malicious files that can be used to obtain remote code execution, | https://github.com/samiba6/CVE-2021-42362 | POC Details |
No public POC found.
Login to generate AI POCNo comments yet