WordPress 的 Dc Woocommerce Multi Vendor 插件在 5.0.18 及更低版本中,存在通过 REST 端点的 参数触发的 SQL 注入漏洞。该漏洞源于对用户传入参数转义不足,且对已有 SQL 查询语句缺乏充分的预处理机制——具体而言,该参数值被直接拼接至 SQL 的 ORDER BY 子句中,而所使用的 函数仅能防止字符突破单引号或双引号字符串字面量,无法提供有效防护。因此,具备供应商级别及以上权限(即拥有 能力)的认证攻击者,可借此向现有 SQL 查询语句后附加恶意 SQL 查询
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| wcmp | MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions | ≤ 5.0.18 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wcmp | MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions | 0 ~ 5.0.18 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet