# Responsive Accordion Slider <=1.2.2 未授权滑块更新漏洞
## 概述
WordPress Responsive Accordion Slider 插件中的 `resp_accordion_silder_save_images` 函数因缺少权限检查,导致存在未授权数据修改漏洞。
## 影响版本
1.2.2 及以下所有版本
## 细节
该漏洞源于 `resp_accordion_silder_save_images` 函数未执行适当的用户能力(capability)检查。攻击者在已认证的情况下,可直接调用该函数。
## 影响
拥有 Contributor 及以上权限的已认证攻击者可修改任意幻灯片的图像元数据,包括标题、描述、alt 文本和链接。
是否为 Web 类漏洞: 未知
判断理由:
| # | POC 描述 | 源链接 | 神龙链接 |
|---|
标题: ERROR: The request could not be satisfied -- 🔗来源链接
标签:
神龙速读:
### 关键信息
- **Error Code:** 403 ERROR
- **Message:** The request could not be satisfied.
- **Error Details:**
- Request blocked.
- Cannot connect to the server for the app or website at this time.
- Possible reasons: Too much traffic or a configuration error.
- Suggestions: Try again later, contact the app or website owner.
- Additional Information: Review CloudFront documentation for troubleshooting steps if providing content to customers through CloudFront.
- **Generated by:** cloudfront (CloudFront)
- **Request ID:** h8WrwigWqJ_HTGFKxHN4f_fb979kj05qKAWePTpebzSf2_rjDlTpYw==
Zaproxy alias impedit expedita quisquam pariatur exercitationem. Nemo rerum eveniet dolores rem quia dignissimos.