WordPress 的 CV Builder – Professional Resume Builder SaaS 插件存在未经授权的文件上传漏洞。该漏洞存在于 1.3.1 及更早版本中,原因是在 函数中缺少权限检查。这使得未经身份验证的攻击者能够将任意内容作为 PNG 文件上传到 WordPress 的上传目录中。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| bestwpdeveloper | WP CV Builder | ≤ 1.3.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| bestwpdeveloper | WP CV Builder | 0 ~ 1.3.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet