该 WordPress 插件“Advanced Contact Form 7 DB”在 2.1.3 及更早的所有版本中均存在授权绕过漏洞。原因该插件未能正确验证用户是否拥有执行某项操作的权限。这使得拥有自定义级别(custom-level)或更高权限的已认证攻击者能够向该插件管理的任意 Contact Form 7 表单中导入伪造的 CSV 提交记录。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| vsourz1td | Advanced Contact form 7 DB | 0 ~ 2.1.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet