WordPress 的 Divi Essential 插件在 5.8.1 及之前版本中存在敏感信息泄露漏洞,攻击者可通过 和 这两个 AJAX 操作发起攻击。 这些处理函数仅在有条件地验证 nonce(该检查仅在存在 'nonce' POST 参数时执行,且可通过省略该参数轻松绕过),且从未调用 或以其他方式强制执行权限能力。这使得具有订阅者(Subscriber)及以上权限的已认证攻击者能够枚举 WordPress 数据库中的每一个表,并从任意表中读取由调用者指定数量的行数据——包括 (包含用户名、邮箱、哈希密码
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Divi Essential | Divi Essentials | 0 ~ 5.8.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet