WordPress 的 MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO 插件在所有版本至 4.2.1(含)均存在通过 URL 路径进行通用 SQL 注入的漏洞。该漏洞源于对用户传入参数缺乏足够的转义,且对已有 SQL 查询缺乏充分的预处理。这使得拥有订阅者(subscriber)及以上权限的已认证攻击者能够将额外的 SQL 查询附加到现有的查询中,从而用于从数据库中获取敏感信息。 该漏洞仅在特定条件下可被利用:当 短代码在网站
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| themeisle | MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO | 0 ~ 4.2.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet