漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
WP Compress <= 7.10.09 - Cross-Site Request Forgery to Arbitrary Options Deletion
Vulnerability Description
The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.10.09. This is due to missing or incorrect nonce validation on the (top-level template code) function. This makes it possible for unauthenticated attackers to delete arbitrary WordPress options, including critical ones such as siteurl, home, active_plugins, template, and stylesheet, causing site outage or a full plugin and theme reset via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Vulnerability Type
跨站请求伪造(CSRF)
Vulnerability Title
WordPress WP Compress 跨站请求伪造漏洞
Vulnerability Description
WordPress WP Compress是WordPress基金会的一款网站性能优化插件。 WordPress WP Compress 7.10.09及之前版本存在跨站请求伪造漏洞,该漏洞源于(top-level template code)函数缺少或不正确的nonce验证,可能导致未经身份验证的攻击者通过伪造请求删除任意WordPress选项,包括siteurl、home、active_plugins、template和stylesheet等关键选项,导致网站中断或插件和主题完全重置,且需要诱使站点管
CVSS Information
N/A
Vulnerability Type
N/A