WordPress 的 WP File Download 插件在所有版本中均存在任意文件删除漏洞,原因是其 函数对文件路径的验证不足。这使得具有订阅者级别或更高权限的已认证攻击者可以删除服务器上的任意文件。如果删除了关键文件(例如 ),很容易导致远程代码执行。 该利用过程分为两个阶段: 1. 第一个请求发送至 任务,将路径遍历字符串持久化到文件元数据中; 2. 第二个请求发送至 任务,以触发 调用。 这两个端点均缺少权限检查(capability checks)和非CE(nonce)验证。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| JoomUnited | WP File Download | 0 ~ 6.3.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet