WordPress 插件 Paytium: Mollie payment forms & donations 在所有 5.0.3 及以下版本中存在权限提升漏洞。在 5.0.3 补丁中,开发人员为 字段引入了 / 签名验证机制,但遗漏了另一个过滤器函数 。该函数注册在 钩子上,且在已签名的构建逻辑之后执行,它未经验证签名就将 的所有键值原样复制到支付元数据数组中。 攻击者可以利用这一点,通过提交未经验证的 值来覆盖已签名路径中的输出。随后, 函数会读取持久化的 文章元数据,并将其直接作为角色参数传递给 函数。这使得未
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| paytiumsupport | Paytium: Mollie payment forms & donations | ≤ 5.0.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| paytiumsupport | Paytium: Mollie payment forms & donations | 0 ~ 5.0.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet