漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Members <= 3.2.22 - Unauthenticated Sensitive Information Disclosure via REST API Pagination Side Channel
Vulnerability Description
The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.22 via the members_filter_protected_posts_for_rest. This makes it possible for unauthenticated attackers to extract determine the existence and exact count of access-restricted posts, and use per-page pagination as a boolean oracle to infer keywords and content contained within those hidden restricted posts.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
信息暴露
Vulnerability Title
WordPress Members 信息泄露漏洞
Vulnerability Description
WordPress Members是WordPress基金会的一个内容管理系统组件。 WordPress Members 3.2.22及之前版本存在信息泄露漏洞,该漏洞源于通过members_filter_protected_posts_for_rest函数暴露敏感信息,可能导致未经验证的攻击者提取存在访问限制的文章的确切数量,并利用分页推断隐藏文章中的关键词和内容。
CVSS Information
N/A
Vulnerability Type
N/A