漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Abandoned Contact Form 7 <= 2.2 - Missing Authorization to Unauthenticated Arbitrary Post Deletion via 'recover_id' Parameter
Vulnerability Description
The Abandoned Contact Form 7 plugin for WordPress is vulnerable to unauthorized arbitrary post deletion in versions up to, and including, 2.2. This is due to a missing capability check and missing nonce validation in the action__remove_abandoned() function, which is registered to both the wp_ajax_remove_abandoned and wp_ajax_nopriv_remove_abandoned hooks. The handler takes a user-supplied recover_id parameter from $_POST and passes it directly to wp_delete_post() with the force-delete flag set to true, without verifying that the ID belongs to the plugin's own cf7af_data post type. This makes it possible for unauthenticated attackers to permanently delete arbitrary posts, pages, or other content on the affected site by sending a single admin-ajax.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Vulnerability Type
授权机制缺失
Vulnerability Title
zealopensource Abandoned Contact Form 7 授权问题漏洞
Vulnerability Description
zealopensource Abandoned Contact Form 7是zealopensource开源的一款自动追踪废弃联系表单的WordPress插件。 zealopensource Abandoned Contact Form 7 2.2及之前版本存在授权问题漏洞,该漏洞源于action__remove_abandoned()函数缺少权限检查和随机数验证,可能导致未经身份验证的攻击者通过发送admin-ajax请求,永久删除受影响网站上的任意文章、页面或其他内容。
CVSS Information
N/A
Vulnerability Type
N/A