WordPress 插件 Booking Calendar 在所有 11.8.2 及以下版本中存在权限提升漏洞,该漏洞可通过 AJAX 操作被利用。 漏洞成因在于: 函数仅对通过 显式注册的选项名称应用逐选项安全防护措施。因此,对于任何未注册的选项名称(包括 WordPress 核心选项), 将返回空策略,从而绕过所有 、 和 检查。与此同时,攻击者可控的 参数仅经过 处理,随后被直接传递给 ,且未施加任何额外限制。 这使得拥有编辑(Editor)级别或更高权限的已认证攻击者能够提升其权限至管理员(Administ
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| wpdevelop | Booking Calendar | ≤ 11.8.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wpdevelop | Booking Calendar | 0 ~ 11.8.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet