WordPress Request a Quote是WordPress基金会的一款报价请求插件。 WordPress Request a Quote 2.5.5及之前版本存在输入验证错误漏洞,该漏洞源于对emd_delete_file AJAX操作中的$_POST['path']参数处理不当,导致未经验证的攻击者可以调用任意零参数PHP函数,例如phpinfo(),可能暴露敏感服务器配置和凭据或执行其他破坏性内置PHP函数。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| emarket-design | Request a Quote – Quote Forms for Any WordPress Site | ≤ 2.5.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| emarket-design | Request a Quote – Quote Forms for Any WordPress Site | 0 ~ 2.5.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet