WordPress和WordPress plugin都是WordPress基金会的产品。WordPress是一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。WordPress plugin是一个应用插件。 WordPress plugin RSVP and Event Management Plugin 存在安全漏洞,该漏洞源于2.7.8 之前的 RSVP 和事件管理插件 WordPress 插件在导出其条目时没有任何授权检查,并且具有与 init 操作挂钩的导
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| Unknown | RSVP and Event Management Plugin | 2.7.2 ~ 2.7.2* | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | WordPress RSVP and Event Management plugin before 2.7.8 is susceptible to missing authorization. The plugin does not have any authorization checks when exporting its entries, and the export function is hooked to the init action. An attacker can potentially retrieve sensitive information such as first name, last name, and email address of users registered for events, | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-1054.yaml | POC详情 |
未找到公开 POC。
登录以生成 AI POC| CVE-2022-0994 | WordPress和WordPress plugin 跨站脚本漏洞 | |
| CVE-2022-1112 | WordPress plugin Autolinks 跨站脚本漏洞 | |
| CVE-2022-1091 | WordPress plugin sanitisation step of the Safe SVG 跨站脚本漏洞 | |
| CVE-2022-1090 | WordPress plugin Good & Bad Comments跨站脚本漏洞 | |
| CVE-2022-1088 | WordPress plugin Page Security & Membership 跨站脚本漏洞 | |
| CVE-2022-1063 | WordPress plugin Thank Me Later 跨站脚本漏洞 | |
| CVE-2022-1037 | WordPress plugin EXMAGE 代码问题漏洞 | |
| CVE-2022-1020 | WordPress plugin WooCommerce 安全漏洞 | |
| CVE-2022-1001 | WordPress和WordPress plugin 跨站脚本漏洞 | |
| CVE-2021-25120 | WordPress plugins Easy Social Feed Free 跨站脚本漏洞 | |
| CVE-2022-0879 | WordPress plugin Caldera Forms跨站脚本漏洞 | |
| CVE-2022-0785 | WordPress plugin Daily Prayer Time SQL注入漏洞 | |
| CVE-2022-0780 | WordPress plugin 跨站脚本漏洞 | |
| CVE-2022-0765 | WordPress和WordPress plugin 跨站脚本漏洞 | |
| CVE-2022-0737 | WordPress plugin Text Hover 跨站脚本漏洞 | |
| CVE-2022-0707 | WordPress和WordPress plugin 跨站请求伪造漏洞 | |
| CVE-2022-0706 | WordPress plugin Easy Digital Downloads 跨站脚本漏洞 | |
| CVE-2022-0661 | WordPress plugin Ad Injection代码注入漏洞 |
暂无评论