WordPress 的 CTX Feed Pro 插件存在代码注入漏洞,影响版本范围为所有版本直至并包括 7.6.12 版本。该漏洞是由于对“Feed 配置”字段的输入验证不足所致,该字段值被直接传递给 PHP 的 eval() 函数执行。这使得拥有管理员级别或更高级别权限的已认证攻击者能够在服务器上执行任意 PHP 代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| CTX | CTX Feed Pro | 0 ~ 7.6.12 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet