该描述涉及 PDF Builder for WooCommerce 插件。以下是这段漏洞描述的中文翻译: WooCommerce 的 PDF Builder 插件 允许用户创建发票、装箱单等文档。该插件在所有 2.0.11 及更早的版本中均存在授权绕过(Authorization Bypass)漏洞。 根本原因:插件未正确验证执行特定操作的用户是否拥有相应权限。 影响:这允许具有“订阅者(subscriber)”或更高权限的已认证攻击者,通过提供任意有效的 和 值,并搭配一个无效的(垃圾)nonce 值,从而获取任
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| edgarrojas | PDF Builder for WooCommerce. Create invoices,packing slips and more | ≤ 2.0.11 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| edgarrojas | PDF Builder for WooCommerce. Create invoices,packing slips and more | 0 ~ 2.0.11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet