ayecode userswp是ayecode公司的一个用户管理与注册插件。 AyeCode UsersWP 1.2.63及之前版本存在授权问题漏洞,该漏洞源于对用户控制键的验证缺失,容易受到不安全的直接对象引用攻击,可能导致通过清理uwp_usermeta表中的avatar_thumb或banner_thumb元数据,重置或永久删除包括管理员在内的任意用户的头像或横幅图像。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| stiofansisland | UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP | ≤ 1.2.63 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| stiofansisland | UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP | 0 ~ 1.2.63 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet