WordPress 的 PPOM – Product Addons & Custom Fields for WooCommerce 插件存在任意文件删除漏洞。该漏洞源于 函数中对文件路径验证不足,影响所有 34.0.10 及更早版本。攻击者无需认证即可删除服务器上的任意文件,若删除关键文件(如 wp-config.php),极易导致远程代码执行。此外,被删除的文件会以字节相同的方式移动至公开的 wp-content/uploads/ppom_files/confirmed/ 目录,这意味着攻击者还可通过该机制读取服
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| themeisle | PPOM – Product Addons & Custom Fields for WooCommerce | 0 ~ 34.0.10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet