WordPress 的 “WordLift – AI 驱动的 SEO 与 Schema” 插件在 3.54.10 及之前所有版本中,存在敏感信息泄露漏洞。 具体原因如下:该插件通过 REST API 注册了 路由(包括 、 、 、 以及 ),并将 设置为 ;同时,下游转换器在获取文章时直接使用 ,而未校验文章状态或请求用户的权限。 这导致未认证的 attackers 可以通过枚举文章 ID 的方式,读取私有(private)、草稿(draft)和待审核(pending)文章的标题、内容/描述、作者、发布与修改日期、
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wordlift | WordLift – AI powered SEO – Schema | 0 ~ 3.54.10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet