WordPress 的 Post Duplicator 插件存在漏洞,导致在版本 3.0.11 及更早版本中,由于 函数缺少权限检查,允许未经授权的数据修改。该函数在接受通过 REST 端点传入的 参数时,并未验证用户是否具备 能力。这使得具有贡献者及以上级别的已认证攻击者能够创建以任意用户(包括管理员)名义发布的重复帖子。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| metaphorcreations | Post Duplicator | ≤ 3.0.11 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| metaphorcreations | Post Duplicator | 0 ~ 3.0.11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet