WordPress 插件 Otter Blocks(Gutenberg 区块、Gutenberg 编辑器及 FSE 的页面构建器)在所有 3.2.6 及以下版本中存在敏感信息泄露漏洞,该漏洞通过 'otter_form_widget_filter' 参数触发。这使得具备订阅者级别或以上权限的已认证攻击者能够提取最近五次表单提交者的电子邮件地址、提交日期以及站点表单提交的总数。只要主题选项 'themeisle_blocks_form_emails' 非空(在保存任意 Form 区块后的正常状态下即满足此条件),该小
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| themeisle | Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE | 0 ~ 3.2.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet