WordPress 插件 LearnPress – WordPress LMS Plugin for Create and Sell Online Courses(用于创建和销售在线课程的 WordPress 学习管理系统插件)在 4.4.8 及更早版本中存在不安全的直接对象引用(IDOR)漏洞。该漏洞通过暴露于公共 (即 )端点的 回调函数触发。 该端点被明确列在 类的“无需 nonce(防 CSRF 令牌)”白名单中,且未执行任何权限检查。 处理函数仅依据攻击者提供的单一标识符( )进行授权判断,但在获取返回的
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| thimpress | LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | 0 ~ 4.4.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet