WordPress 的 Simply Schedule Appointments 插件在所有版本(包括 1.6.12.27 及之前)中存在本地文件包含(Local File Inclusion, LFI)漏洞,该漏洞通过 参数触发。这使得拥有订阅者(subscriber)级别或更高权限的已认证攻击者能够包含并执行服务器上的任意 文件,从而执行这些文件中包含的任意 PHP 代码。该漏洞可被用于绕过访问控制、获取敏感数据,或在允许上传并包含 文件类型的情况下实现代码执行。值得注意的是,在实际利用中该漏洞无需身份验证即可
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| croixhaug | Simply Schedule Appointments | 0 ~ 1.6.12.27 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet