WordPress 的 Super Forms – Drag & Drop Form Builder 插件在所有版本(包括 6.3.316 及之前)中存在权限提升漏洞。该漏洞源于 Register & Login 附加组件中的 函数:该函数将客户端提交的 键加入白名单,并将其直接复制到传递给 的用户数据数组中,但未对提交的 role 值进行以下任何验证: 未与管理员配置的 进行比对; 未使用允许列表(allow-list)机制; 未执行 权限检查。 因此,未经身份验证的攻击者可以通过向任何已发布的 Super Fo
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| WebRehab | Super Forms – Drag & Drop Form Builder | 0 ~ 6.3.316 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet