WordPress 的 LearnPress 插件在 4.4.4 及更早版本中存在漏洞,攻击者可通过 AJAX 操作未经授权的任意 WordPress 选项修改。LP_Admin_Ajax::create_page() 处理程序仅检查 edit_pages 权限和一个 wp_rest nonce(两者均可供编辑器级别用户访问),然后从请求中读取 field_name 参数,未将其限制在 learn_press_* 允许列表内,就直接将其作为选项键传递给 LP_Helper::create_page(),后者调用 u
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| thimpress | LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | 0 ~ 4.4.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet