漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
WPFunnels <= 3.12.8 - Authenticated (Funnel Manager+) Privilege Escalation via 'group_id' Path Parameter
Vulnerability Description
The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Privilege Escalation via arbitrary option update in all versions up to, and including, 3.12.8. This is due to the `update_settings()` REST callback failing to validate the `group_id` path parameter against an allowlist of permitted option names before passing it directly to `get_option()` and `update_option()`, allowing the built-in `wp_user_roles` option — which satisfies the route's loose `[\w-]+` regex — to be targeted. This makes it possible for authenticated attackers with the `wpf_manage_funnels` capability and above to elevate their privileges to administrator by writing a crafted role definition containing arbitrary capabilities into the `wp_user_roles` option, thereby granting any WordPress role full site administrator access. The `wpf_manage_funnels` capability is typically assigned to the Funnel Manager custom role created by the plugin, meaning this role is the minimum required to exploit the vulnerability.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
特权管理不恰当
Vulnerability Title
WordPress WPFunnels 权限许可和访问控制问题漏洞
Vulnerability Description
WordPress WPFunnels是WordPress基金会的一款能够提升平均订单价值和转化率的 WooCommerce 销售漏斗构建工具。 WordPress WPFunnels 3.12.8及之前版本存在权限许可和访问控制问题漏洞,该漏洞源于`update_settings()` REST回调未能对`group_id`路径参数进行允许列表验证,直接传递参数至`get_option()`和`update_option()`,导致攻击者可通过写入特制的角色定义到`wp_user_roles`选项中来提
CVSS Information
N/A
Vulnerability Type
N/A