WordPress 的 Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots 插件在 2.15.33 及更早的所有版本中均存在授权绕过漏洞。该漏洞是由于插件未能正确验证执行某项操作的用户是否具备相应权限所致。这使得拥有自定义级别或更高权限的已认证攻击者能够无需额外身份验证即可访问任意聊天室线程的完整消息记录、线程元数据以及用户数据。此漏洞仅在聊天室的 设置保持其默认值 时才可被利用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wordplus | Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots | 0 ~ 2.15.33 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet