WordPress 插件 s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions 在所有版本直至并包括 260814 版本中,存在通过 参数导致远程代码执行(RCE)的安全漏洞。该漏洞的产生原因是: 参数在通过 函数进行清理时,仅移除了正则表达式中的反向引用(regex backreferences),而未过滤 PHP 标签;随后该参数被代入由 执行的“
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| clavaque | s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions | ≤ 260814 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| clavaque | s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions | 0 ~ 260814 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet