WordPress 的 Photo Reviews for WooCommerce 插件在 1.2.30 及更早版本中存在任意内容删除漏洞。该漏洞源于:插件在公开评论提交过程中,从 参数中获取攻击者可控制的帖子 ID,并将其存入评论元数据( )中,但未验证这些 ID 是否属于提交者所拥有的附件;此外,在删除评论时, 处理函数会对每个存储的 ID 无条件调用 。因此,未认证的攻击者可以导致网站上任意的帖子、页面、产品或媒体附件被永久删除,只要管理员随后删除该攻击者提交的评论,或 WordPress 内置的 定时任务在
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| villatheme | Photo Reviews for WooCommerce | 0 ~ 1.2.30 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet