Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
JetFormBuilder <= 3.6.3 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'context' Parameter
Vulnerability Description
The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to retrieve every distinct value stored under any arbitrary wp_postmeta key on the site — including WooCommerce billing PII such as _billing_email, _billing_phone, and _billing_address fields, order totals, attachment paths, and any third-party plugin credentials or tokens stored in post meta — provided at least one published JetFormBuilder form with a get_from_db generator field exists on the site. Exploitation requires that the target site has at least one published jet-form-builder post containing a field whose generator_function is set to get_from_db; an attacker must supply a matching form ID, field name, and generator ID in the request, but all of these can be discovered by browsing the site's public forms.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
授权机制缺失
Vulnerability Title
Jetmonsters JetFormBuilder 授权问题漏洞
Vulnerability Description
JetFormBuilder是Jetmonsters组织的一个WordPress表单构建插件。 Jetmonsters JetFormBuilder 3.6.3及之前版本存在授权问题漏洞,该漏洞源于未正确验证用户是否被授权执行操作,可能导致未经身份验证的攻击者检索站点上任意wp_postmeta键下存储的所有不同值,包括WooCommerce账单个人信息、订单总额、附件路径以及存储在post meta中的第三方插件凭据或令牌。
CVSS Information
N/A
Vulnerability Type
N/A