WordPress 插件 Nelio Content – Editorial Calendar & Social Media Auto-Posting 在所有 4.5.0 及以下版本中存在权限绕过漏洞。该漏洞源于插件未正确验证用户是否具有执行特定操作所需的授权。攻击者只要拥有“贡献者”(contributor)或更高权限,即可永久删除任何可复用的社交消息(nc_reusable_social 类型文章),包括由管理员或其他高权限用户创建的社交消息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| nelio | Nelio Content – Editorial Calendar & Social Media Auto-Posting | 0 ~ 4.5.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet