WooMS WordPress 插件版本 9.14 及之前版本中,未对用户提供的 URL 进行验证便将其用于服务端请求,并在每个此类请求中附加已存储的第三方集成凭据,这使得未经身份验证的攻击者可以执行服务端请求伪造(SSRF),并在相关数据同步功能启用时泄露已配置的集成凭据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet