WordPress和WordPress plugin都是WordPress基金会的产品。WordPress是一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。WordPress plugin是一个应用插件。 WordPress plugin Extensive VC Addons for WPBakery page builder 1.9.1 版本之前存在路径遍历漏洞,该漏洞源于加载模板时没有验证传递的参数。
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| Unknown | Extensive VC Addons for WPBakery page builder | 0 ~ 1.9.1 | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | Automatic Mass Tool for checking vulnerability in CVE-2023-0159 - Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated LFI | https://github.com/im-hanzou/EVCer | POC详情 |
| 2 | The plugin does not validate a parameter passed to the php extract function when loading templates, allowing an unauthenticated attacker to override the template path to read arbitrary files from the hosts file system. This may be escalated to RCE using PHP filter chains. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-0159.yaml | POC详情 |
| 3 | Automatic Mass Tool for checking vulnerability in CVE-2023-0159 - Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated… | https://github.com/Sn20393873/Extensive | POC详情 |
未找到公开 POC。
登录以生成 AI POC| CVE-2022-4551 | WordPress plugin Rich Table of Contents 跨站脚本漏洞 | |
| CVE-2023-0060 | WordPress plugin Responsive Gallery Grid 跨站脚本漏洞 | |
| CVE-2022-4448 | WordPress plugin GiveWP 跨站脚本漏洞 | |
| CVE-2023-0362 | WordPress plugin Themify Portfolio Post 跨站脚本漏洞 | |
| CVE-2022-4445 | WordPress plugin FL3R FeelBox SQL注入漏洞 | |
| CVE-2022-4783 | WordPress plugin Youtube Channel Gallery 跨站脚本漏洞 | |
| CVE-2022-4473 | WordPress plugin Widget Shortcode 跨站脚本漏洞 | |
| CVE-2023-0379 | WordPress plugin Spotlight Social Feeds 跨站脚本漏洞 | |
| CVE-2023-0270 | WordPress plugin YaMaps for WordPress Plugin 跨站脚本漏洞 | |
| CVE-2023-0220 | WordPress plugin Pinpoint Booking System plugin SQL注入漏洞 | |
| CVE-2022-4678 | WordPress plugin TemplatesNext ToolKit 跨站脚本漏洞 | |
| CVE-2023-0373 | WordPress plugin Lightweight Accordion 跨站脚本漏洞 | |
| CVE-2023-0261 | WordPress plugin WP TripAdvisor Review Slider SQL注入漏洞 | |
| CVE-2022-4458 | WordPress plugin amr shortcode any widget 跨站脚本漏洞 | |
| CVE-2023-0169 | WordPress plugin Zoho Forms 跨站脚本漏洞 | |
| CVE-2023-0260 | WordPress plugin WP Review Slider SQL注入漏洞 | |
| CVE-2023-0333 | WordPress plugin TemplatesNext ToolKit 跨站脚本漏洞 | |
| CVE-2022-4546 | WordPress plugin Mapwiz SQL注入漏洞 | |
| CVE-2023-0061 | WordPress plugin Judge.me Product Reviews for WooCommerce 跨站脚本漏洞 | |
| CVE-2023-0098 | WordPress plugin Simple URLs SQL注入漏洞 |
显示前 20 条,共 47 条。 查看全部 → →
暂无评论