WordPress WPFunnels是WordPress基金会的一款能够提升平均订单价值和转化率的 WooCommerce 销售漏斗构建工具。 WordPress WPFunnels 3.12.7及之前版本存在代码注入漏洞,该漏洞源于对'logKey'参数处理不当,可能导致经过身份验证的管理员在服务器上包含任意.php文件并执行任意PHP代码,从而绕过访问控制、获取敏感数据或实现代码执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| getwpfunnels | WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell | ≤ 3.12.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| getwpfunnels | WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell | 0 ~ 3.12.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet