WordPress Nex Forms是WordPress基金会开源的一个表单构建插件。 WordPress Nex Forms 9.2.3及之前版本存在路径遍历漏洞,该漏洞源于delete_file() AJAX处理程序从数据库检索文件路径并直接传递给unlink()函数,且未进行路径验证(未检查realpath、basename或白名单),同时insert_record() AJAX处理程序允许同一认证用户在location列存储任意值,可能导致经过身份验证的攻击者删除服务器上的任意文件,包括wp-c
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| webaways | NEX-Forms – Ultimate Forms Plugin for WordPress | ≤ 9.2.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| webaways | NEX-Forms – Ultimate Forms Plugin for WordPress | 0 ~ 9.2.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet