WordPress 的“预约与活动日历 – Amelia”插件在所有版本(包括 2.4.5 及之前版本)中存在未授权数据修改漏洞。该漏洞源于插件在验证支付时,直接接受客户端提供的套餐兑换标识符作为付款凭证,而缺乏有效的校验机制。这使得未认证的攻擊者可以在未完成支付的情况下,创建处于“已批准”状态的预约。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| melograno | Booking for Appointments and Events Calendar – Amelia | 0 ~ 2.4.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet