WordPress和WordPress plugin都是WordPress基金会的产品。WordPress是一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。WordPress plugin是一个应用插件。 WordPress Plugin BuddyForms 2.7.8之前版本存在安全漏洞,该漏洞源于存在不安全的反序列化问题,未经身份验证的攻击者利用该漏洞可以反序列化数据并调用任意的PHP对象。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | BuddyForms WordPress Plugin | All versions prior to version 2.7.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Exploit for CVE-2023-26326 in the WordPress BuddyForms plugin, leveraging CVE-2024-2961 for remote code execution. This exploit bypasses PHP 8+ deserialization limitations by chaining vulnerabilities with php://filter. | https://github.com/omarelshopky/exploit_cve-2023-26326_using_cve-2024-2961 | POC Details |
| 2 | None | https://github.com/mesudmammad1/CVE-2023-26326_Buddyform_exploit | POC Details |
No public POC found.
Login to generate AI POC| CVE-2023-23296 | Korenix Technology Korenix JetWave 资源管理错误漏洞 | |
| CVE-2023-26468 | Cerebrate 安全漏洞 | |
| CVE-2023-26462 | Thingsboard 信任管理问题漏洞 | |
| CVE-2023-26325 | WordPress Plugin ReviewX WordPress SQL注入漏洞 | |
| CVE-2023-24317 | Judging Management System 代码问题漏洞 | |
| CVE-2023-24212 | Tenda AX3 缓冲区错误漏洞 | |
| CVE-2023-24205 | Clash 安全漏洞 | |
| CVE-2023-24104 | Ubiquiti Networks UniFi Dream Machine 安全漏洞 | |
| CVE-2023-23917 | Rocket.Chat 安全漏洞 | |
| CVE-2023-23916 | curl 安全漏洞 | |
| CVE-2023-23915 | curl 安全漏洞 | |
| CVE-2023-23914 | curl 安全漏洞 | |
| CVE-2022-3219 | GnuPG 缓冲区错误漏洞 | |
| CVE-2023-23295 | Korenix Technology Korenix JetWave 命令注入漏洞 | |
| CVE-2023-23294 | Korenix Technology Korenix JetWave 命令注入漏洞 | |
| CVE-2023-0597 | Linux kernel 安全漏洞 | |
| CVE-2023-0044 | Red Hat quarkus-vertx-http 跨站脚本漏洞 | |
| CVE-2022-48341 | Thingsboard 安全漏洞 | |
| CVE-2022-46786 | SquaredUp Dashboard Server SCOM Edition 跨站脚本漏洞 | |
| CVE-2022-46785 | SquaredUp Dashboard Server SCOM Edition 跨站脚本漏洞 |
Showing top 20 of 24 CVEs. View all on vendor page → →
No comments yet