用于 WordPress 的 WooCommerce Checkout Custom Fields Builder 插件在 1.1.5 及之前的所有版本中,由于未正确验证用户是否有权执行特定操作,存在授权绕过(Authorization Bypass)漏洞。 这意味着任何拥有订阅者(subscriber)级别及以上权限的已认证攻击者,可以安装并激活一个由攻击者托管的任意插件,从而在服务器上实现远程代码执行(Remote Code Execution, RCE)。 该漏洞利用了以下事实:当 WooCommerce 处
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| stylemix | Checkout Custom Fields Builder for WooCommerce | 0 ~ 1.1.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet