WordPress 的 Post Grid and Gutenberg Blocks – ComboBlocks 插件在 2.2.32 至 2.3.1 版本中存在未经身份验证的钩子注入漏洞(Unauthenticated Hook Injection)。该漏洞存在于 文件中的多个函数中。这使得未经验证的攻击者能够在 WordPress 中执行与钩子相关的操作,前提是相关函数中未设置其他安全控制机制。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| pickplugins | Post Grid | 2.2.85 ~ 2.3.32 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet