WordPress 的 EthPress – Web3 登录插件(EthPress – Web3 Login)在所有不超过 2.3.5 的版本中存在认证绕过漏洞。该漏洞源于 文件中的 函数在签名验证失败分支中缺少 return 语句。当 检测到签名不匹配时,该函数仅将错误信息赋值给局部变量 ,却未中断执行流程,导致代码无条件地继续执行后续登录逻辑块。在此过程中, 函数会无条件调用 设置用户认证 Cookie,无论提交的签名是否有效。 因此,未授权的攻击者可以通过提交任意目标用户(包括管理员账户)关联的钱包地址,并搭
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| lynn999 | EthPress – Web3 Login | 0 ~ 2.3.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet