WordPress 插件 AutomatorWP – Automator 用于无需代码的自动化、Webhook 和自定义集成,在所有版本直至且包括 5.8.4 版本中均存在授权绕过漏洞。该漏洞是由于插件未能正确验证用户是否有权执行特定操作所致。这使得具有订阅者及以上级别权限的已认证攻击者能够检索由站点管理员账户配置的所有 ConvertKit 表单数据,从而暴露原本仅对插件管理员开放的集成详细信息。由于所需的 nonce(一次性令牌)在每次加载管理页面时都会被本地化设置,因此任何能够访问 /wp-admin 路径的
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| rubengc | AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress | ≤ 5.8.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| rubengc | AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress | 0 ~ 5.8.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet