WordPress 插件 Super Forms – Drag & Drop Form Builder 在所有不超过 6.3.316 的版本中均存在任意目录删除漏洞,该漏洞可通过 submit_form 函数触发。此漏洞的成因在于:对攻击者可控的 JSON 字段声明与实际表单结构之间的验证不足,同时 ABSPATH(WordPress 根目录路径)检查机制失效——dirname() 函数可通过简单去除末尾斜杠轻易绕过该保护机制。这使得未经身份验证的攻击者能够递归删除服务器上的任意目录,包括 WordPress 的根
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| WebRehab | Super Forms – Drag & Drop Form Builder | 0 ~ 6.3.316 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet