WordPress 的 PPWP – Password Protect Pages 插件在 1.9.18 及之前版本中存在 PHP 对象注入漏洞,该漏洞是由于对来自易受攻击参数 “post_protection_roles” 的不可信输入进行反序列化所致。这使得拥有贡献者(Contributor)级别及以上权限的已认证攻击者能够注入 PHP 对象。 由于易受攻击的软件本身不包含任何已知的 POP(Property-Oriented Programming)链,因此该漏洞在没有其他包含 POP 链的插件或主题的情况下
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| buildwps | PPWP – Password Protect Pages | ≤ 1.9.18 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| buildwps | PPWP – Password Protect Pages | 0 ~ 1.9.18 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet