WordPress 的 MemberDash 插件在 1.8.5 及之前的所有版本中,由于“id”参数缺乏对用户可控键的验证,存在不安全直接对象引用(IDOR)漏洞。这使得未认证的攻击者可以在注册时提供任意用户 ID,从而更改任何 WordPress 用户(包括管理员)的密码,并在不向受害者发送任何通知的情况下接管其账户。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| LearnDash | MemberDash | 0 ~ 1.8.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet