WordPress 的 YITH WooCommerce Waitlist Premium 插件存在权限提升漏洞,受影响版本为 3.35.0 及之前版本。该漏洞原因是:注册在 动作上的 函数既缺少权限(capability)检查,也缺少 nonce 校验,并且使用 + 从 中导入攻击者可控的变量,这些变量随后会被传递给 和 。这使得拥有 Subscriber(订阅者)及以上权限的已认证攻击者能够创建新的用户账户并将其角色设置为管理员,从而将自身权限提升至管理员级别。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Yith | YITH WooCommerce Waitlist Premium | 0 ~ 3.35.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet