WordPress WC Vendors是WordPress基金会开源的一款多供应商市场插件。 WordPress WC Vendors 2.7.0及之前版本存在SQL注入漏洞,该漏洞源于对'status'参数的用户输入转义不足,且对现有SQL查询准备不足,可能导致经过身份验证的具有shop manager级别及以上权限的攻击者在现有查询中追加额外SQL查询,从而提取数据库中的敏感信息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| wcvendors | WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors | ≤ 2.7.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wcvendors | WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors | 0 ~ 2.7.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet