WordPress 的 Blocksy Companion 插件在 2.1.58 及以下版本中存在权限提升漏洞。该漏洞源于 AJAX 处理器显式禁用了 Dokan 的 vendor 注册 nonce 验证(通过添加过滤器 ),随后在处理过程中盲目信任攻击者提供的 参数值,并将其传递给 和 函数。 这使得未认证的攻击者能够将自身权限提升至 Dokan 的“卖家”(vendor)账户级别——即使站点明确关闭了 Dokan 卖家注册功能,该漏洞依然有效。攻击者一旦完成权限提升,即可自动登录该卖家账户,从而获得超出普通客户
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| creativethemeshq | Blocksy Companion | 0 ~ 2.1.58 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet