WordPress 的 WPFunnels 插件存在“缺失授权”(Missing Authorization)漏洞,影响版本从早期版本至 3.12.13(含该版本)。 漏洞原因在于:该插件为已认证和未认证( )用户都注册了名为 的 AJAX 动作,而底层的 函数未进行以下任何一项安全校验: 1. 未进行 nonce(防重放令牌)验证; 2. 未进行用户能力(权限)检查; 3. 未验证攻击者提供的 是否确实是攻击者提供的 中实际配置的优惠产品。 这使得未认证的攻击者能够将任意 WooCommerce 商品以任意漏斗步
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| getwpfunnels | WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell | 0 ~ 3.12.13 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet