WordPress StoreEngine是WordPress基金会开源的一款电商系统组件。 WordPress StoreEngine 2.1.1及之前版本存在路径遍历漏洞,该漏洞源于parse_file_path函数存在路径遍历问题,可能导致具有供应商级别及以上访问权限的经过身份验证的攻击者读取服务器上任意文件的内容,其中可能包含敏感信息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| kodezen | StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More | ≤ 2.1.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| kodezen | StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More | 0 ~ 2.1.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet