WordPress 的 YOP Poll 插件在所有版本中(包括 7.0.10 及更早版本)存在源验证错误漏洞。该漏洞是由于插件通过 将 非ces 令牌发送至 时,使用了通配符 作为 参数,从而未严格校验来源域。这使得未经身份验证的攻击者可以窃取属于已登录管理员的 REST 非ces 令牌,并利用该令牌修改管理员的电子邮件地址和密码,最终导致管理员账户被完全接管。要利用此漏洞,管理员必须访问由攻击者控制的网页。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| yourownprogrammer | YOP Poll | 0 ~ 7.0.10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet