漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Premium Packages <= 7.0.4 - Authentication Bypass to Non-Admin via 'wpdmppdl' Parameter
Vulnerability Description
The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 7.0.4 via the `wpdmppdl` parameter. This is due to the `download()` function — hooked to the unauthenticated WordPress `wp` action — decoding the attacker-controlled `wpdmppdl` parameter using only `base64_decode()` and `json_decode()` with no HMAC, cryptographic signature, or nonce verification, and then issuing WordPress authentication cookies after a domain check that is trivially bypassed because both sides of the comparison are attacker-supplied values. This makes it possible for unauthenticated attackers to authenticate as any non-administrator WordPress user, including subscribers, customers, contributors, authors, editors, and shop managers, who owns an order, gaining full session-level access to that account.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
认证机制不恰当
Vulnerability Title
WordPress Premium Packages – Sell Digital Products Securely 授权问题漏洞
Vulnerability Description
WordPress Premium Packages – Sell Digital Products Securely是WordPress基金会的一款通过安全方式销售数字产品的软件包。 WordPress Premium Packages – Sell Digital Products Securely 7.0.4及之前版本存在授权问题漏洞,该漏洞源于download()函数对wpdmppdl参数仅使用base64_decode()和json_decode()解码且无HMAC或加密签名或随机数验证,导致身
CVSS Information
N/A
Vulnerability Type
N/A