WordPress 插件 “Automation Web Platform – WooCommerce 的通知与 OTP” 以及 “Advanced Country Code” 在版本 4.8.6 及以下存在身份验证绕过漏洞。该漏洞源于 函数在响应公开的 OTP 请求时,会直接返回用于登录的秘密令牌(magic login token),而非仅将该令牌发送至用户注册的电子邮件地址。因此,如果攻击者知晓目标用户的电子邮件地址,即可无需身份验证而以该用户(包括管理员)身份登录网站。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| 101gen | Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code | ≤ 4.8.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| 101gen | Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code | 0 ~ 4.8.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet