WordPress Question Answer是WordPress基金会开源的一款问答功能的CMS插件。 WordPress Question Answer 1.2.73及之前版本存在SQL注入漏洞,该漏洞源于通过'id' GET参数的用户输入清理不充分,结合wp_unslash()移除魔法引号保护,直接拼接到SQL查询中,导致未经身份验证的攻击者能够追加SQL查询,从而提取数据库敏感信息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| pickplugins | PickPlugins Question Answer | ≤ 1.2.73 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| pickplugins | PickPlugins Question Answer | 0 ~ 1.2.73 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet