WordPress 的 Hello Plus 插件在所有 1.7.7 及以下版本中存在权限绕过漏洞。该漏洞是由于插件未正确验证用户是否具备执行某项操作的权限所致。这使得拥有贡献者(Contributor)级别及以上权限的攻击者能够发布自己的 Hello+ 页眉/页脚模板,并起草其他更高权限用户当前正在使用的模板。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| elemntor | Hello Plus | ≤ 1.7.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| elemntor | Hello Plus | 0 ~ 1.7.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet