WordPress Happyforms是WordPress基金会的一款表单构建组件。 WordPress Happyforms 1.26.12及之前版本存在代码注入漏洞,该漏洞源于happyforms_get_form_partial()函数容易受到本地文件包含攻击,导致认证攻击者(管理员及以上权限)能够包含并执行服务器上任意.php文件,从而绕过访问控制、获取敏感数据或实现代码执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| happyforms | Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms | ≤ 1.26.12 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| happyforms | Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms | 0 ~ 1.26.12 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet