WordPress 插件 ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF 在 6.5.5 及之前所有版本中存在 PHP 对象注入漏洞,该漏洞由对不可信输入的反序列化操作引起。这使得具有作者权限或更高权限的已认证攻击者能够注入 PHP 对象。目前该受影响的软件中不存在已知的 POP(Payload Object Property)链,因此除非目标站点同时安装了包含 POP 链的其他插件或主题,否则此漏洞不会造成实际影响。如果目标系统上
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| shortpixel | ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF | ≤ 6.5.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| shortpixel | ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF | 0 ~ 6.5.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet