WordPress 的 Welcomizer 插件在所有版本(包括 2.8.1 及之前)中存在远程代码执行漏洞。该漏洞源于 AJAX 操作中 'savesection' 处理器缺少授权检查,并结合了使用 函数在前端执行用户提供的“自定义逻辑”代码。 具体而言, 中的 AJAX 处理器虽然验证了 nonce(一次性令牌),但在 情况下未进行 权限检查。此外,nonce 通过可直接访问的 文件暴露给任何已认证用户,该文件会加载 WordPress 并输出 nonce。 这使得具有“订阅者”(Subscriber)级别或
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| sebwordpress | The Welcomizer | 0 ~ 2.8.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet