WordPress 的 The Events Made Easy 插件存在本地文件包含漏洞,该漏洞影响所有 3.2.5 及以下版本,漏洞位于 函数中。此漏洞允许具有贡献者及以上权限的已认证攻击者在服务器上包含并执行任意 .php 文件,从而执行这些文件中的任意 PHP 代码。当 .php 类型文件可以被上传并被包含时,该漏洞可用于绕过访问控制、获取敏感数据,或在特定条件下实现代码执行。存储型的遍历负载在任意访客加载受影响的事件单页时被被动触发,这意味着在发布内容后无需攻击者额外交互即可触发执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| liedekef | Events Made Easy | ≤ 3.2.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| liedekef | Events Made Easy | 0 ~ 3.2.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet