WordPress 的 WooCommerce 帮助台工单支持系统插件(Helpdesk Support Ticket System for WooCommerce)在所有版本(包括 2.1.6 及以下)中存在不安全的直接对象引用(Insecure Direct Object Reference)漏洞。该漏洞源于对用户可控的 ‘id’ 参数缺乏验证。这使得具有订阅者(subscriber)及以上权限的经过身份认证的攻击者,能够通过从管理员页脚获取 nonce 值,并向删除处理程序提供任意 stsw_response
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| wpcodefactory | Helpdesk Support Ticket System for WooCommerce | ≤ 2.1.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wpcodefactory | Helpdesk Support Ticket System for WooCommerce | 0 ~ 2.1.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet