WordPress Content Egg是WordPress基金会开源的一款适用于WordPress和WooCommerce的联盟营销插件。 WordPress Content Egg 11.3.0及之前版本存在路径遍历漏洞,该漏洞源于对cegg_data post metadata中'img_file'字段验证不足,导致路径遍历,可能允许经过身份验证的攻击者(具有作者级别及以上权限)删除服务器上的任意文件,进而可能导致远程代码执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| keywordrush | Content Egg – Affiliate Product Importer & Price Comparison | ≤ 11.3.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| keywordrush | Content Egg – Affiliate Product Importer & Price Comparison | 0 ~ 11.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet