WordPress 插件“The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe”在 32.0.1 及以下的所有版本中存在未认证任意文件覆盖漏洞,原因是“baseUrlForFacebook”参数的文件路径验证不足。这使得拥有订阅者权限或更高权限的已认证攻击者能够覆盖已知文件,在满足特定前置条件的情况下,可能导致远程代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| contest-gallery | Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe | 0 ~ 32.0.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet