WordPress 的 SEO Booster 插件存在授权缺失漏洞,受影响版本为 7.4.7 及更早版本。该漏洞源于 函数缺少权限检查:该函数挂载于 钩子,直接处理 和 ,但未验证调用者的角色。这使得拥有订阅者(Subscriber)及以上权限的已认证攻击者,可以通过访问一个构造好的 URL,覆盖 、 和 选项,并删除 标志。这将导致 Google 搜索控制台(Google Search Console)集成被扰乱,并通过攻击者提供的令牌触发一次外发至 Google API 的请求,其响应数据被存储到站点选项中,
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| cleverplugins | SEO Booster | 0 ~ 7.4.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet