Ninja Forms - Save Progress WordPress 插件在 3.0.30 及更早版本中存在缺失授权(Missing Authorization)漏洞。该漏洞是由于 函数中缺少权限检查(capability checks)和非空(nonce)验证所致。这使得拥有订阅者(subscriber)或更高权限的已认证攻击者能够删除 数据表中的任意数据库记录(例如已保存的表单提交数据)。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Saturday Drive | Ninja Forms - Save Progress | ≤ 3.0.30 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Saturday Drive | Ninja Forms - Save Progress | 0 ~ 3.0.30 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet