WordPress 插件 “Ninja Forms – The Contact Form Builder That Grows With You” 在所有版本中(包括 3.14.6 及之前版本)均存在 PHP 对象注入漏洞,源于对不可信输入的反序列化处理。该漏洞使得拥有管理员级别或更高权限的已认证攻击者能够注入 PHP 对象。 目前,受影响的软件本身不存在已知的 POP 链(Property-Oriented Programming chain),这意味着除非站点上安装了包含 POP 链的其他插件或主题,否则该漏洞
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| kstover | Ninja Forms – The Contact Form Builder That Grows With You | 0 ~ 3.14.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet