WordPress 的 Awesome Support 插件在 6.3.9 及之前版本中易受“缺失授权”(Missing Authorization)漏洞影响。该漏洞源于 函数缺少能力(capability)检查:与对应的 函数不同,它未强制要求 或 ,而仅依赖一个未针对目标用户进行作用域限定的 nonce。这使得拥有订阅者(subscriber)级别或更高权限的已认证攻击者能够对任意用户账户(包括管理员)设置 标志,从而永久阻止其经过审核的激活流程,并向受害用户发送拒绝通知邮件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| awesomesupport | Awesome Support – WordPress HelpDesk & Support Plugin | 0 ~ 6.3.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet