WordPress 的 Really Simple Security 插件在 9.8.2 版本之前存在一个“缺少授权检查”的漏洞。该漏洞允许经过认证的、低权限的攻击者通过利用个人资料页面更新处理程序中一条未加保护的代码路径,无限期地绕过强制的二因素身份验证(2FA)。 具体来说,攻击者可以构造一个未包含二因素身份验证字段的 POST 请求,从而跳过 nonce 验证并触发 函数。该函数会在每次登录周期中重置宽限期的锚点时间戳,导致强制 2FA 的执行被无限期推迟。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| reallysimpleplugins | Really Simple Security | < 9.8.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| reallysimpleplugins | Really Simple Security | 0 ~ 9.8.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet