WordPress 插件 WS Form LITE – Drag & Drop Contact Form Builder 存在 PHP 对象注入漏洞,影响版本范围为所有不超过 1.10.80 的版本。该漏洞源于对用户提交的表单元值中未经校验的数据进行了反序列化操作,导致未认证的远程攻击者可注入恶意 PHP 对象。 然而,该易受攻击的软件本身不包含已知的 POP(Property Oriented Programming,面向属性编程)链,因此单独利用此漏洞不会产生实际影响,除非目标网站上还安装了其他包含 POP 链
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| westguard | WS Form LITE – Drag & Drop Contact Form Builder | ≤ 1.10.80 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| westguard | WS Form LITE – Drag & Drop Contact Form Builder | 0 ~ 1.10.80 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet