WordPress 的 WP Data Access 插件在所有 ≤ 5.5.68 版本中存在不安全的直接对象引用(IDOR)漏洞,该漏洞存在于 函数中,原因是缺少对用户可控键的验证。这使得未认证的攻击者可以通过利用授权检查(针对 app_id 执行)与数据检索(使用 cnt_id 执行,但未验证容器所有权)之间的不匹配,从而访问受保护应用容器的数据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| peterschulznl | WP Data Access – App Builder for Tables, Forms, Charts, Maps & Dashboards | ≤ 5.5.68 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| peterschulznl | WP Data Access – App Builder for Tables, Forms, Charts, Maps & Dashboards | 0 ~ 5.5.68 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet