WordPress 的 Flamingo 插件存在授权绕过漏洞,影响 2.6.2 及之前所有版本。该漏洞源于插件未能正确验证用户是否具有执行相应操作的权限。因此,拥有贡献者(contributor)及以上权限的已认证攻击者可以利用此漏洞枚举分类术语(taxonomy terms),包括从 Contact Form 7 表单标题中派生的频道名称(这些名称可能暴露内部表单用途、部门名称或工作流标识符),以及每个频道的提交数量和联系标签名称。该插件的 过滤器虽然限制了用户访问 Flamingo 的管理界面,但这一限制并未
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| rocklobsterinc | Flamingo | ≤ 2.6.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| rocklobsterinc | Flamingo | 0 ~ 2.6.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet