# Ultimate Member小于2.6.7 - 无需认证的权限提升
## 漏洞概述
Ultimate Member WordPress插件在2.6.7版本之前允许访问者创建具有任意权限的用户账户,攻击者可以随意创建管理员账户。此漏洞目前正被积极利用。
## 影响版本
- Ultimate Member WordPress插件版本2.6.7之前
## 漏洞细节
该漏洞源于插件未能防止访问者创建具有任意权限的用户账户,从而导致攻击者可以随意创建具有管理员权限的账户。
## 漏洞影响
攻击者可以利用此漏洞创建管理员账户,进而全面控制WordPress站点,对网站安全构成严重威胁。
# | POC 描述 | 源链接 | 神龙链接 |
---|---|---|---|
1 | Exploit for CVE-2023-3460. Unauthorized admin access for Ultimate Member plugin < v2.6.7 | https://github.com/gbrsh/CVE-2023-3460 | POC详情 |
2 | None | https://github.com/rizqimaulanaa/CVE-2023-3460 | POC详情 |
3 | Mass CVE-2023-3460. | https://github.com/yon3zu/Mass-CVE-2023-3460 | POC详情 |
4 | CVE-2023-3460 | https://github.com/Fire-Null/CVE-2023-3460 | POC详情 |
5 | Exploit and scanner for CVE-2023-3460 | https://github.com/diego-tella/CVE-2023-3460 | POC详情 |
6 | Exploit for the vulnerability of Ultimate Member Plugin. | https://github.com/Rajneeshkarya/CVE-2023-3460 | POC详情 |
7 | GitHub repository for CVE-2023-3460 POC | https://github.com/BlackReaperSK/CVE-2023-3460_POC | POC详情 |
8 | CVE-2023-3460 | https://github.com/EmadYaY/CVE-2023-3460 | POC详情 |
9 | None | https://github.com/julienbrs/exploit-CVE-2023-3460 | POC详情 |
10 | GitHub repository for CVE-2023-3460 POC | https://github.com/DiMarcoSK/CVE-2023-3460_POC | POC详情 |
11 | Cái này dựng lên với mục đích cho ae tham khảo, chê thì đừng có xem. :)))) | https://github.com/TranKuBao/CVE-2023-3460_FIX | POC详情 |
12 | The plugin does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create administrator accounts at will. This is actively being exploited in the wild. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-3460.yaml | POC详情 |
13 | None | https://github.com/GURJOTEXPERT/CVE-2023-3460 | POC详情 |
暂无评论