WordPress 的“预约与活动日历 – Amelia(Premium)”插件在 8.0 至 9.6.2 版本中存在权限提升漏洞。该漏洞源于客户更新端点中对攻击者可控的 'type' 参数缺乏充分校验。攻击者可以利用该缺陷,将自身角色设置为 'manager',并在 'externalId' 参数设为 0 时,触发系统创建一个具有 'wpamelia-manager' 角色的 WordPress 用户。这使得未认证的攻击者能够首先将权限提升至管理员级别:先将自身角色提升为经理,随后创建一个关联到某个管理员用户 I
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| melograno | Booking for Appointments and Events Calendar – Amelia | 8.0 ~ 9.6.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet