WordPress和WordPress plugin都是WordPress基金会的产品。WordPress是一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。WordPress plugin是一个应用插件。 WordPress plugin Popup by Supsystic 1.10.9 之前版本存在访问控制错误漏洞,该漏洞源于在AJAX操作中没有任何身份验证和授权。攻击者利用该漏洞可以调用并获取订阅用户的电子邮件地址。
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| Unknown | Popup by Supsystic | 1.10.9 ~ 1.10.9 | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | The Popup by Supsystic WordPress plugin before 1.10.9 does not have any authentication and authorisation in an AJAX action, allowing unauthenticated attackers to call it and get the email addresses of subscribed users | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-0424.yaml | POC详情 |
未找到公开 POC。
登录以生成 AI POC| CVE-2022-1338 | WordPress plugin Easy Generate Rest API Url 跨站脚本漏洞 | |
| CVE-2022-1303 | WordPress plugin Slide Anything 跨站脚本漏洞 | |
| CVE-2022-1171 | WordPress plugin Vertical scroll recent post 跨站脚本漏洞 | |
| CVE-2022-1104 | WordPress plugin Popup Maker 跨站脚本漏洞 | |
| CVE-2022-1047 | WordPress plugin Themify Builder 跨站脚本漏洞 | |
| CVE-2022-1013 | WordPress plugin Personal Dictionary SQL注入漏洞 | |
| CVE-2022-0948 | WordPress plugin Order Listener for WooCommerce SQL注入漏洞 | |
| CVE-2022-0898 | WordPress plugin IgniteUp 跨站脚本漏洞 | |
| CVE-2022-0874 | WordPress plugin WP Social Buttons跨站脚本漏洞 | |
| CVE-2022-0836 | WordPress plugin SEMA API SQL注入漏洞 | |
| CVE-2022-0826 | WordPress plugin WP Video Gallery SQL注入漏洞 | |
| CVE-2022-0817 | WordPress plugin BadgeOS SQL注入漏洞 | |
| CVE-2022-0814 | WordPress plugin Ubigeo de Peru SQL注入漏洞 | |
| CVE-2022-0625 | WordPress plugin Admin Menu Editor 跨站脚本漏洞 | |
| CVE-2022-0592 | WordPress plugin MapSVG SQL注入漏洞 | |
| CVE-2019-25060 | WordPress plugin WPGraphQL 访问控制错误漏洞 |
暂无评论