WordPress 的 Reviso Exporter for WooCommerce 插件存在未授权数据修改漏洞,原因是 函数缺少权限检查和 nonce 验证,该漏洞影响版本 1.2.3 及之前版本。 该函数被注册为 AJAX 操作,并会无条件调用 ,从而删除用于身份验证 API 调用的 Reviso 协议授权令牌(Agreement Grant Token)。 这使得拥有订阅者(Subscriber)级别及以上权限的已认证攻击者能够删除插件存储的协议授权令牌,进而破坏 WooCommerce 与 Reviso
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ghera74 | ilGhera Reviso Exporter for WooCommerce | 0 ~ 1.2.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet