# WordPress Yet Another Related Posts Plugin (YARPP) 插件 <= 5.30.10 - 访问控制缺陷漏洞
## 概述
YARPP 中存在访问控制漏洞。
## 影响版本
从 n/a 到 5.30.10 版本的 YARPP 均受影响。
## 细节
YARPP 允许未经授权的访问控制行为,导致潜在的安全风险。
## 影响
此漏洞可能允许攻击者进行未经授权的操作或访问敏感数据。
# | POC 描述 | 源链接 | 神龙链接 |
---|---|---|---|
1 | YARPP <= 5.30.10 - Missing Authorization | https://github.com/RandomRobbieBF/CVE-2024-43919 | POC详情 |
2 | The YARPP Yet Another Related Posts Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in the ~/includes/yarpp_pro_set_display_types.php file in all versions up to, and including, 5.30.10. This makes it possible for unauthenticated attackers to set display types. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-43919.yaml | POC详情 |
标题: WordPress Yet Another Related Posts Plugin (YARPP) plugin <= 5.30.10 - Broken Access Control vulnerability - Patchstack -- 🔗来源链接
标签: vdb-entry
神龙速读暂无评论