WordPress 插件 “ThemeAtelier Domain For Sale” 在 3.5.2 版本之前存在授权缺失漏洞,其 REST API 端点允许未经身份验证的攻击者访问并操作受保护的资源。攻击者可以检索已存储的报价记录、通过数字标识符删除任意报价,并访问仪表盘统计数据,从而泄露竞拍者联系方式、报价详情、消息、验证令牌以及业务数据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ThemeAtelier | Domain For Sale | < 3.5.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ThemeAtelier | Domain For Sale | 0 ~ 3.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet