WordPress Demi是WordPress基金会开源的一款功能强大的 WordPress 演示导入、备份和网站迁移插件。 WordPress Demi 0.0.8及之前版本存在信息泄露漏洞,该漏洞源于handle_restore_step函数缺少HTTP访问控制,导致wp-content/uploads/demi-backup-state/目录暴露加密恢复密钥,可能使未经身份验证的攻击者复制任意文件到攻击者控制的服务器位置。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| deveasel | Demi – One Click Demo Import, Backup & Site Migration | ≤ 0.0.8 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| deveasel | Demi – One Click Demo Import, Backup & Site Migration | 0 ~ 0.0.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet