WordPress 的 Paid Membership 插件(Ecommerce, 用户注册表单, 登录表单, 用户个人资料及内容限制)——ProfilePress 插件,在所有 4.17.4 及以下版本中存在敏感信息泄露漏洞,该漏洞通过 get_user_profile_structure 函数引入。这使得具备订阅者级别及以上权限的已认证攻击者,能够在成员目录中通过每行用户重新绑定时,利用攻击者控制的 base64 载荷在 [pp-custom-html] 短代码中调用 [profile-email]、[prof
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| properfraction | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress | 0 ~ 4.17.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet