WordPress和WordPress plugin都是WordPress基金会的产品。WordPress是一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。WordPress plugin是一个应用插件。 WordPress Plugin Download Monitor 存在信息泄露漏洞。目前尚无此漏洞的相关信息,请随时关注CNNVD或厂商公告。
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| WPChill | Download Monitor | n/a ~ 4.7.60 | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | Download Monitor <= 4.7.60 - Sensitive Information Exposure via REST API | https://github.com/RandomRobbieBF/CVE-2022-45354 | POC详情 |
| 2 | CVE-2022-45354 Download Monitor <= 4.7.60 - Sensitive Information Exposure via REST API | https://github.com/NekomataCode/CVE-2022-45354 | POC详情 |
| 3 | The Download Monitor plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.7.60 via REST API. This can allow unauthenticated attackers to extract sensitive data including user reports, download reports, and user data including email, role, id and other info (not passwords) | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-45354.yaml | POC详情 |
未找到公开 POC。
登录以生成 AI POC暂无评论