WordPress 的 Formidable Charts 插件在所有版本(包括 2.0.1 及更早版本)中均存在目录遍历漏洞,攻击向量为 参数。该漏洞使得未认证的攻击者能够读取服务器上任意文件的内容,而这些文件可能包含敏感信息。成功利用此漏洞需要同时激活 Formidable Forms Lite、Formidable Forms Pro 和 Formidable Charts 这三个插件,并且服务器上必须存在 目录(通常是在渲染了图像格式图表后才会出现)。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Strategy11 | Formidable Charts | ≤ 2.0.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Strategy11 | Formidable Charts | 0 ~ 2.0.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet