WordPress 的 Better Messages – 聊天室、群聊、私信及 AI 聊天机器人 插件在所有 2.15.33 及更早的版本中,存在通过身份伪造导致的信息泄露漏洞。 该漏洞的根本原因在于 函数通过检查访客记录中存储的 IP 地址是否以 为前缀,来识别具有特权的内部 AI 机器人账号。然而,这个 IP 地址是在未经身份验证的访客注册过程中,直接从客户端可控的 请求头中逐字填入的。 这使得未经身份验证的攻击者能够注册一个被插件视为其内部 AI 机器人的访客身份,从而绕过每个聊天室的允许角色列表、草稿状态
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wordplus | Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots | 0 ~ 2.15.33 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet