WordPress Shibboleth是WordPress基金会的一个身份认证插件。 WordPress Shibboleth 2.5.4之前版本存在授权问题漏洞,该漏洞源于启用HTTP标头身份模式时未设置反欺骗密钥,无法正确验证身份信息,可能导致未经验证的攻击者通过伪造的身份标头登录,并在自动账户创建和默认管理员角色映射开启时,创建并登录为新的管理员。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Shibboleth | < 2.5.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Shibboleth | 0 ~ 2.5.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-11579 | Kali Forms < 2.4.17 - Unauthenticated Media Upload | |
| CVE-2026-11580 | Kali Forms < 2.4.17 - Contributor+ Arbitrary Post Metadata Disclosure via IDOR | |
| CVE-2026-12512 | Quotes Llama < 3.1.6 - Unauthenticated SQL Injection via sc Parameter |
No comments yet