WordPress 插件 InfusedWoo Pro 在 5.1.17 及更早版本中存在权限提升漏洞,该漏洞源于账户接管机制的缺陷。问题出在 函数中缺少适当的权限检查,该函数仅使用 作为唯一授权验证方式,导致低权限用户可以渲染任意电子邮件地址的邮件预览合并字段。此漏洞允许具有订阅者及以上级别的认证攻击者生成并获取任何 WordPress 用户(包括管理员)的有效密码重置链接,从而实现账户接管。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Infused Addons | InfusedWoo Pro | ≤ 5.1.17 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Infused Addons | InfusedWoo Pro | 0 ~ 5.1.17 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet