WordPress Easy Post Submission是WordPress基金会开源的一款简化文章提交流程的CMS插件。 WordPress Easy Post Submission 2.3.0及之前版本存在授权问题漏洞,该漏洞源于create_post()函数缺少能力检查,可能导致未经身份验证的攻击者通过postId参数修改任意文章标题、内容、摘要、分类和标签,并将文章状态改为草稿(取消发布)。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| themeruby | Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPress | ≤ 2.3.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| themeruby | Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPress | 0 ~ 2.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet