WordPress Live Composer是WordPress基金会开源的一款可视化网页设计插件。 WordPress Live Composer 2.1.18及之前版本存在反序列化注入漏洞,该漏洞源于对不受信任输入的反序列化,可能导致PHP对象注入,具有贡献者级别及以上权限的已认证攻击者可利用该漏洞,若存在POP链可能删除任意文件、检索敏感数据或执行代码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| livecomposer | Live Composer – Free WordPress Website Builder | ≤ 2.1.18 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| livecomposer | Live Composer – Free WordPress Website Builder | 0 ~ 2.1.18 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet