WordPress 的 Woo PDF Invoice Builder 插件(也以 “PDF Builder for WooCommerce” 名称分发)在所有版本至 2.0.8(含 2.0.8)中存在不安全直接对象引用(IDOR) 漏洞。 漏洞原因: 位于 第 513 行的 AJAX 处理器,通过 注册。该处理器在根据攻击者通过 POST 字段 指定的订单号加载任意订单并序列化其完整的 和 meta 数据返回响应之前,未进行权限(capability)检查,也未进行 nonce 验证。 影响: 任何拥有 Subs
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| edgarrojas | PDF Builder for WooCommerce. Create invoices,packing slips and more | 0 ~ 2.0.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet