WordPress WP Encryption是WordPress基金会的一款网站加密组件插件。 WordPress WP Encryption 7.8.6.6及之前版本存在路径遍历漏洞,该漏洞源于通过'imploded'参数存在目录遍历,可能允许具有管理员权限的认证攻击者读取服务器上的任意文件内容,其中可包含敏感信息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| gowebsmarty | WP Encryption – Lifetime Free SSL Cert & HTTPS, Force SSL / HTTPS Redirect, SSL Security | ≤ 7.8.6.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| gowebsmarty | WP Encryption – Lifetime Free SSL Cert & HTTPS, Force SSL / HTTPS Redirect, SSL Security | 0 ~ 7.8.6.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet