WordPress 的 WooCommerce 插件“Customer Reviews for WooCommerce”在所有版本至 5.120.0(包括 5.120.0)均存在授权绕过漏洞。该漏洞源于插件未能正确验证用户是否具有执行特定操作的权限。攻击者无需认证即可永久删除媒体库中的任意附件,包括管理员拥有的产品图片、徽标和文档。具体而言,攻击者可通过将目标附件的 ID 注入到一条待回收站清理的评论中,从而触发删除操作。 利用该漏洞需要获取一个公开可用的评论表单链接(该链接包含通过电子邮件发送给顾客的 13 位十
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ivole | Customer Reviews for WooCommerce | ≤ 5.120.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ivole | Customer Reviews for WooCommerce | 0 ~ 5.120.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet