WordPress 插件 “The Listdom: AI-powered Business Directory with Classifieds Ads Listings” 存在任意文件删除漏洞。该漏洞源于 函数中文件路径验证不足,影响所有 6.1.2 及之前版本。此漏洞允许具备管理员及以上权限的认证攻击者在服务器上删除任意文件,从而极易导致远程代码执行(尤其是当被删除的文件为关键系统文件如 时)。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| webilia | Listdom: AI-powered Business Directory with Classifieds Ads Listings | ≤ 6.1.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| webilia | Listdom: AI-powered Business Directory with Classifieds Ads Listings | 0 ~ 6.1.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet