WordPress RapiSafe是WordPress基金会开源的一款内容管理系统的功能扩展插件。 WordPress RapiSafe 1.0.4及之前版本存在路径遍历漏洞,该漏洞源于handleAjaxRemoveUpload函数文件路径验证不足,可能导致未经身份验证的攻击者删除服务器上的任意文件,进而导致远程代码执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| pietror91 | RapiSafe – Secure Multi File Upload for Contact Form 7 | ≤ 1.0.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| pietror91 | RapiSafe – Secure Multi File Upload for Contact Form 7 | 0 ~ 1.0.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet