WordPress 中的 Themify Builder 插件在所有不高于 7.8.0 的版本中存在身份验证绕过漏洞。该漏洞是由于插件未能正确验证用户是否具有执行操作的权限所致。攻击者可以通过提供其控制的帖子 ID 和 JSON 样式的载荷,未经授权地修改任意帖子(包括私有帖子和草稿)中存储的 Themify Builder 样式数据(填充和内边距属性)。由于处理程序所需的 nonce(一次性令牌)会通过 函数自动发布到所有由构建器渲染的前端页面,因此任何未认证的用户都可以从页面源代码中轻松获取有效的 nonce,
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| themifyme | Themify Builder | ≤ 7.8.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| themifyme | Themify Builder | 0 ~ 7.8.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet