WordPress WP-DownloadManager是WordPress基金会的一款下载管理插件。 WordPress WP-DownloadManager 1.68.11版本和6.9.4版本存在任意文件上传漏洞,该漏洞源于文件上传处理中对文件扩展名和MIME类型验证不足,且目标路径拼接未净化的输入,导致具有管理员权限的攻击者可通过download-add.php上传任意文件并直接执行,从而导致远程代码执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| wp-downloadmanager | wp-downloadmanager | ≤ 1.69 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wp-downloadmanager | wp-downloadmanager | 0 ~ 1.69 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet