WordPress和WordPress plugin都是WordPress基金会的产品。WordPress是一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。WordPress plugin是一个应用插件。 WordPress Plugin The Easy Digital Downloads 3.1.0.4 版本之前存在SQL注入漏洞,该漏洞源于 edd_download_search 的 s 参数存在 SQL 注入问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | Easy Digital Downloads WordPress Plugin | < 3.1.0.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | WordPress Easy Digital Downloads plugin 3.1.0.2 and 3.1.0.3 contains a SQL injection vulnerability in the s parameter of its edd_download_search action. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-23489.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2022-48125 | TOTOLINK A7100RU 操作系统命令注入漏洞 | |
| CVE-2023-24021 | ModSecurity 安全漏洞 | |
| CVE-2023-23492 | WordPress Plugin The Login with Phone Number SQL注入漏洞 | |
| CVE-2023-22964 | ZOHO ManageEngine ServiceDesk Plus 授权问题漏洞 | |
| CVE-2023-22912 | MediaWiki 安全特征问题漏洞 | |
| CVE-2023-22910 | MediaWiki 跨站脚本漏洞 | |
| CVE-2023-0101 | Nessus 安全漏洞 | |
| CVE-2022-48279 | ModSecurity 安全漏洞 | |
| CVE-2022-48152 | RemoteClinic SQL注入漏洞 | |
| CVE-2022-48126 | TOTOLINK A7100RU 操作系统命令注入漏洞 | |
| CVE-2023-23010 | Ecommerce-CodeIgniter-Bootstrap多款产品 跨站脚本漏洞 | |
| CVE-2022-48124 | TOTOLINK A7100RU 操作系统命令注入漏洞 | |
| CVE-2022-48123 | TOTOLINK A7100RU 操作系统命令注入漏洞 | |
| CVE-2022-48122 | TOTOLINK A7100RU 操作系统命令注入漏洞 | |
| CVE-2022-48121 | TOTOLINK A7100RU 操作系统命令注入漏洞 | |
| CVE-2022-48120 | Hospital Management System SQL注入漏洞 | |
| CVE-2022-47747 | kraken 路径遍历漏洞 | |
| CVE-2022-47732 | Yeastar N412和Yeastar N824 安全漏洞 | |
| CVE-2022-47024 | Vim 代码问题漏洞 | |
| CVE-2022-47021 | opusfile 代码问题漏洞 |
Showing top 20 of 72 CVEs. View all on vendor page → →
No comments yet