漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
Vulnerability Description
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
N/A
Vulnerability Title
WordPress SQL注入漏洞
Vulnerability Description
WordPress是WordPress基金会开源的一套使用PHP语言开发的博客平台。该平台具有在基于PHP和MySQL的服务器上架设个人博客网站的功能。 WordPress存在SQL注入漏洞,该漏洞源于未正确清理WP_Query的author__not_in参数,可能导致SQL注入攻击。以下版本受到影响:6.8.6之前版本的6.8.x版本、6.9.5之前版本的6.9.x版本和7.0.2之前版本的7.0.x版本。
CVSS Information
N/A
Vulnerability Type
N/A