WordPress 插件“Unlimited Elements For Elementor”在 2.0.16 及更早版本中,其 'addontype' 参数存在 SQL 注入漏洞。该漏洞源于对用户输入参数的转义不足,以及 getWhereString() 函数中现有 SQL 查询缺乏充分的预处理。具体而言,当该参数以数组形式提供时,数组的零号元素会被直接用作 SQL 比较运算符,并未经消毒处理就拼接进 WHERE 子句;同时,normalizeAjaxInputData() 函数会移除 WordPress 的魔术引
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| unitecms | Unlimited Elements For Elementor | 0 ~ 2.0.16 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet