WordPress 的 Sigma Forms Pro 插件在所有版本中(包括 1.4.5 及更早版本)存在远程代码执行(RCE)漏洞,该漏洞通过 函数触发。其根本原因是插件在处理表单提交时,动态地赋予所有用户 权限,并且在未配置 时,会绕过 MIME 类型验证。这使得未经身份验证的攻击者能够在服务器上执行代码。多个默认预置模板(如 Job Application、Support Ticket 和 Wholesale Application)中的文件上传字段在设计上未配置任何文件类型限制,因此该漏洞在安装后即可立即
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| bdthemes | SigmaForms Pro – AI Generated Forms | 0 ~ 1.4.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet