WordPress 的 WP EasyCart 插件在 5.9.3 及更早的版本中,存在权限提升漏洞。该漏洞源于 AJAX 处理函数:它会遍历 中的所有键,并直接将其传入 ,且未设置任何白名单限制;同时,该处理函数的执行条件仅为具备 权限或插件自定义的 权限。 插件内置的 角色拥有 权限,但不具备 权限。此外,所需的 nonce 会在前端的产品/分类模板中生成,这些模板会向任何拥有 权限的用户展示。 这使得具备“商店管理员”(Store Manager)或更高权限的已认证攻击者,能够更新任意 WordPress 选
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| levelfourstorefront | Shopping Cart & eCommerce Store | 0 ~ 5.9.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet