WordPress 的 TikTok 插件在 1.4.1 及之前所有版本中存在授权绕过漏洞。这是由于该插件未能正确验证用户是否具有执行某项操作的权限。这使得未认证的 attackers 能够覆盖存储在 中商户的 TikTok 集成访问令牌,从而劫持该网站的 TikTok Business 和产品目录集成。成功利用此漏洞需要攻击者提供商户已注册的 TikTok 应用签发的有效 TikTok OAuth auth_code,因为插件在令牌交换过程中必须先从 TikTok API 收到 的响应,然后才会覆盖存储的访问令牌
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| tiktokbusinessplugin | TikTok | 0 ~ 1.4.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet