WordPress 的 Wow Elements Addons for Elementor 插件在 1.11.2 及之前所有版本中均存在服务端请求伪造(SSRF)漏洞。 该漏洞产生的原因是:插件将来自“Changelog File”设置中的用户可控输入直接传递给 函数,而对 URL 未进行充分的验证或过滤。 这使得拥有 Contributor(贡献者)或更高权限的已认证攻击者能够发起源自 Web 应用的任意位置的网络请求,从而查询甚至修改内部服务中的信息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| wowelements | Wow Elements Addons for Elementor | ≤ 1.11.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wowelements | Wow Elements Addons for Elementor | 0 ~ 1.11.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet