WordPress 插件 TrueBooker – Appointment Booking and Scheduler System 在 1.2.6 及以下版本中,存在“通过用户控制的键进行授权绕过”漏洞,可导致账户接管。该漏洞源于 AJAX 处理程序 在将攻击者提供的 参数直接传递给 之前,未进行任何身份验证或权限检查。因此,未经身份验证的攻击者可以覆盖任何 WordPress 用户(包括管理员)的电子邮件地址,然后通过标准的 WordPress 忘记密码流程,完全接管目标账户。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| themetechmount | TrueBooker – Appointment Booking and Scheduler System | ≤ 1.2.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| themetechmount | TrueBooker – Appointment Booking and Scheduler System | 0 ~ 1.2.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet