Otter Blocks – Gutenberg 插件(Gutenberg 编辑器和 FSE 的区块/页面构建器)在包括 3.1.7 在内的所有版本中,由于 函数中缺少对用户可控键值的验证,存在不安全直接对象引用(IDOR)漏洞。这使得未认证的攻击者能够通过独立操控 Stripe 结账 URL 中的 参数(使其与 参数脱钩),从而以较低成本购买低价商品,同时获得高级商品的使用权限。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| themeisle | Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE | ≤ 3.1.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| themeisle | Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE | 0 ~ 3.1.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet