WordPress 的 Redux Framework 插件在包括 4.5.14 在内的所有版本中均存在授权绕过漏洞。该漏洞源于插件未能正确验证用户是否有权执行特定操作。这使得拥有订阅者(Subscriber)级别及以上权限的已认证攻击者能够删除受影响站点上任意媒体库附件,包括管理员拥有的文件。当通过 方法在用户个人资料页面注册自定义字体(Custom Fonts)字段时,订阅者即可利用此漏洞。因为这样做会导致必需的 nonce 被渲染到订阅者的 页面中,从而使其能够发起恶意请求。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| davidanderson | Redux Framework | 0 ~ 4.5.14 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet