WordPress 的 Divi Membership 插件在 2.2.0 及以下版本中存在权限提升漏洞。该漏洞是由于 函数在确定新用户角色时,遍历所有 WordPress 角色,并使用 函数与攻击者控制的 bcrypt 哈希值进行比对——该哈希值通过 POST 参数 提供,且未对允许的角色进行任何验证或白名单限制。因此,未认证的攻击者可以通过提交一个本地计算得到的、代表 (管理员)角色的 bcrypt 哈希值作为 参数,从而注册具有管理员权限的新账户;当同时提交 时,攻击者将在同一请求中立即以该管理员身份被认证登
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| DiviEngine | Divi Membership | ≤ 2.2.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| DiviEngine | Divi Membership | 0 ~ 2.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet