WordPress 的 Post Duplicator 插件在所有 3.0.11 及更早版本中存在授权绕过漏洞。该漏洞源于 权限回调仅验证了用户是否具备 能力,而未检查请求用户是否拥有 或其他基于状态限制的能力。这使得拥有贡献者(Contributor)及以上权限的认证攻击者能够创建具有“未来(future,即预定时自动发布)”或“私有(private)”状态的重复文章,从而绕过编辑审核流程。此外,REST 端点未强制执行管理员配置的特定文章类型复制限制,允许复制已被明确禁用的文章类型。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| metaphorcreations | Post Duplicator | ≤ 3.0.11 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| metaphorcreations | Post Duplicator | 0 ~ 3.0.11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet