WordPress 的 Rara One Click Demo Import 插件在 1.3.5 之前版本中存在任意文件上传漏洞。拥有管理员权限的经过身份验证的攻击者可以通过向 函数中的三个文件参数传递一个虚假值,从而绕过 WordPress 核心对文件类型的验证检查(该检查由 执行)。攻击者可以上传一个恶意的 PHP 文件到 uploads 目录,并通过 HTTP 执行该文件,进而在 Web 服务器进程中实现远程代码执行(RCE)。此外,该上传文件在插件停用后仍会保留在磁盘上,且不在媒体库中留下记录,从而能够规避
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Rara Themes | Rara One Click Demo Import | 0 ~ 1.3.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet