以下是该漏洞描述的中文翻译: WordPress 的“预约与活动日历 – Amelia”插件存在由于 接口缺失所有权验证,导致未经授权的访问和数据修改漏洞。该漏洞影响所有版本,最高至 2.4.4。 这使得拥有 角色的已认证攻击者能够查看并修改任意客户信息,包括执行密码重置。如果目标 WordPress 用户曾通过 Amelia 进行过预约,攻击者还可能接管其账户(受影响的角色最高为 Editor 角色)。 注意:此漏洞仅影响插件的高级版(Premium 版),且前提是其中存在“员工面板(Employee Panel
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| melograno | Booking for Appointments and Events Calendar – Amelia | 0 ~ 2.4.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet