WordPress 的 WP Project Manager Pro 插件在 4.0.1 及以下的所有版本中均存在 SQL 注入漏洞。该漏洞是由于对用户提供的参数缺乏足够的转义处理,以及对现有 SQL 查询未进行充分的预处理所致。这使得具有订阅者(Subscriber)级别及以上权限的已认证攻击者,能够向已存在的 SQL 查询中附加额外的 SQL 查询语句,从而用于从数据库中提取敏感信息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| wedevs | WP Project Manager Pro | ≤ 4.0.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wedevs | WP Project Manager Pro | 0 ~ 4.0.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet