用于 WordPress 的 Cozy Blocks – Gutenberg 编辑器与 FSE 的页面构建器(含 700+ 模式、58 种区块及模板)插件存在授权绕过漏洞,影响版本为 2.2.17 及更早的所有版本。该漏洞的成因是插件未正确验证用户是否有权执行某项操作。这使得未经身份验证的攻击者能够获取那些本不应公开可见的、处于草稿、待审核、私有或目录隐藏状态的 WooCommerce 商品的信息,包括商品名称、价格、简短描述、图片 URL、永久链接、库存状态以及商品类型。具体而言,多个区块渲染器在未设置登录门槛的
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| cozythemes | Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates | 0 ~ 2.2.17 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet