WordPress 插件“AcyMailing – 终极新闻通讯插件与营销自动化工具”在所有版本(包括 11.0.4 及之前)中存在目录遍历(Directory Traversal)漏洞,攻击向量为 参数。该漏洞允许未经认证的攻击者读取服务器上的任意文件内容,而这些文件可能包含敏感信息。利用此漏洞的前提是,AcyMailing 配置中的“嵌入图片”(Embed images)选项必须处于启用状态。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| acyba | AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress | 0 ~ 11.0.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet