WordPress 的 MemberPress Corporate Accounts 插件在 1.5.39 版本及之前版本中存在权限提升漏洞。该漏洞源于 函数中的批量赋值(mass assignment)缺陷:该函数将原始的 数组直接传递给 ,而未过滤诸如 或 等危险键。这使得拥有企业账户的已认证攻击者(具备订阅者及以上权限)能够通过覆盖现有管理员账户的电子邮件地址,来创建新的管理员账户或劫持现有管理员账户。该漏洞在 1.5.39 版本中已得到部分修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MemberPress | MemberPress Corporate Accounts | 0 ~ 1.5.39 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet