WordPress 的 WP Fusion(Pro)插件在所有版本(包括 3.47.13 及之前)中存在权限提升漏洞。该漏洞源于 ThriveCart 自动登录处理程序中的 函数对 参数的授权检查不足。 这使得拥有“订阅者(Subscriber)”及以上权限的已认证攻击者,在持有 的情况下,能够创建一个具有管理员权限的新用户账户,从而完全掌控该 WordPress 站点。所需的 在插件文档记载的设置流程中会主动共享给 ThriveCart 客户,因此对于曾进行过购买操作的攻击者而言是可见的。该漏洞仅在启用了“Thr
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Very Good Plugins | WP Fusion (Pro) | ≤ 3.47.13 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Very Good Plugins | WP Fusion (Pro) | 0 ~ 3.47.13 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet