WordPress 插件 SigmaForms Pro – AI Generated Forms 存在任意文件删除漏洞。该漏洞源于 函数中文件路径验证不足,影响所有版本,包括 1.4.11 及之前的所有版本。 未认证的攻击者可以利用此漏洞删除服务器上的任意文件。如果删除了关键文件(如 ),则可能导致远程代码执行(RCE)。 攻击流程如下:恶意构造的路径遍历 URL 通过表单上传字段提交并存储在数据库中;当管理员在管理面板中删除对应的提交记录时,即触发文件删除操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| bdthemes | SigmaForms Pro – AI Generated Forms | 0 ~ 1.4.11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet