SiteGround 为 WordPress 开发的 AI Agent 插件存在授权绕过漏洞,影响所有 1.2.7 及以下版本。该漏洞源于插件未正确验证用户是否具有执行特定操作的权限。这使得未认证的攻击者能够将图片上传至 WordPress 媒体库,绕开了通常对贡献者(Contributor)角色施加的 能力限制。此外,具备贡献者及以上权限的已认证攻击者可以轻松满足该接口所需的 nonce 值和权限校验。由于插件将 颁发给所有拥有块编辑器访问权限的用户(包括贡献者),因此缺失对 能力的检查便成为攻击者利用该漏洞的唯
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| siteground | AI Agent by SiteGround | ≤ 1.2.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| siteground | AI Agent by SiteGround | 0 ~ 1.2.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet