WordPress 的 The Events Calendar 插件存在远程代码执行(RCE)漏洞,影响版本为 6.17.3 及更早的所有版本,漏洞入口位于 函数。该漏洞的成因在于对 widget “classes” 映射的验证不足,导致纯数组(plain-array)载荷能够绕过 的对象检查,并最终到达 中的可调用对象调用点。这使得未认证的 attacker(攻击者)能够在服务器上执行任意代码。 要成功利用该漏洞,需满足两个前提条件: 1. 目标站点必须在 tribe_events 类型文章上启用了评论功能; 2
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| stellarwp | The Events Calendar | 0 ~ 6.17.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet