WordPress BuddyPress是WordPress基金会开源的一款可为网站添加用户资料、活动流、群组和私信等社交功能的插件套件。 WordPress BuddyPress 14.3.3及之前版本存在授权问题漏洞,该漏洞源于bp_notifications_action_bulk_manage缺少对用户控制密钥的验证,导致不安全的直接对象引用,可能使具有Subscriber级别及以上权限的已认证攻击者删除、标记为已读或标记为未读其他用户的通知。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| buddypress | BuddyPress | ≤ 14.3.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| buddypress | BuddyPress | 0 ~ 14.3.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet