WordPress 插件 Kirki – Freeform Page Builder, Website Builder & Customizer 在所有不超过 6.3.1 的版本中存在任意短代码执行漏洞。该漏洞是由于插件将用户的 (显示名称)未经过滤地插入到生成的页面标记中,然后在 方法中将整个结果通过 函数执行所致。由于任何用户都可以通过核心的个人资料表单修改其自己的 ,因此,拥有 Subscriber(订阅者)及以上权限的已认证攻击者能够执行任意短代码。当页面是用户集合页面——例如普通的团队页面或成员目录页面时
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| themeum | Kirki – Freeform Page Builder, Website Builder & Customizer | 0 ~ 6.3.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet