WordPress 的 WooCommerce 自定义用户注册字段插件在 2.2.3 版本及更早版本中,存在权限提升(Privilege Escalation)漏洞。 该漏洞的成因是:插件在 函数中,接受来自未认证的 WooCommerce Store API 请求中由攻击者控制的 值,并将其持久化到订单元数据(order meta)中;随后,在挂载到 钩子的 函数中,该值被直接传递给 ,但并未针对插件后台配置的“允许的角色列表”进行验证。 这使得未认证的攻击者能够通过在结账时创建账户,并修改 JSON 请求体,将
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Addify | Custom User Registration Fields for WooCommerce | ≤ 2.2.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Addify | Custom User Registration Fields for WooCommerce | 0 ~ 2.2.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet