WordPress 插件 WPCafe – 餐厅菜单、在线点餐 & 餐桌预订系统在所有 3.0.19 及以下版本中存在授权绕过漏洞。该漏洞源于插件未正确验证用户是否具备执行某项操作的权限。这使得未认证的攻击者能够读取、创建、更新、克隆和删除电子邮件通知流程,包括用攻击者控制的内容覆盖默认的预订确认、取消和管理员警报邮件(这些邮件从网站的合法地址发送),或完全摧毁预订通知流程。这些易受攻击的端点在任何 WPCafe 安装中默认处于激活状态,无需任何配置要求,因为 Email_Automation_Service_Pr
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| arraytics | WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System | ≤ 3.0.19 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| arraytics | WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System | 0 ~ 3.0.19 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet