WordPress ProfilePress是WordPress基金会开源的一款会员管理与用户认证组件。 WordPress ProfilePress 4.16.19及之前版本存在代码注入漏洞,该漏洞源于软件在运行do_shortcode之前未正确验证值,可能导致已认证的订阅者级别及以上攻击者执行任意短代码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| properfraction | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress | ≤ 4.16.19 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| properfraction | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress | 0 ~ 4.16.19 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet