WordPress 插件“The AI Engine – The Chatbot, AI Framework & MCP”在 3.7.7 及更早的所有版本中,由于对用户可控的 'mediaId' 参数缺乏校验,存在不安全直接对象引用(Insecure Direct Object Reference, IDOR)漏洞。这使得拥有订阅者权限或更高权限的已认证攻击者,可以通过提供附件 ID 来访问并获取属于其他用户(包括管理员)的私有音频附件的转录内容。该漏洞要求在插件设置中启用“公共 API”模块;若该模块未启用,则对
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| tigroumeow | AI Engine – The Chatbot, AI Framework & MCP for WordPress | 0 ~ 3.7.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet