Nokri - Job Board WordPress 主题(WordPress)存在通过账户接管导致的权限提升漏洞,影响版本为 1.6.6 及更早的所有版本。 该漏洞源于 函数中重置令牌的验证机制存在不足:攻击者可以提交一个空的令牌,而由于令牌验证逻辑存在缺陷,该空令牌能够与用户元数据(user meta)中为空或未设置的 值匹配成功。 这使得未认证的访问者(unauthenticated attacker)能够重置任意用户(包括管理员)的密码,从而获取其账户访问权限,实现权限提升和账户接管。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| scriptsbundle | Nokri – Job Board WordPress Theme | 0 ~ 1.6.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet