WordPress 的 WPC Shop as a Customer for WooCommerce 插件在所有版本(包括 2.0.0)中均存在通过账户接管导致的权限提升漏洞。该漏洞源于插件在颁发新的身份验证会话之前,未对目标用户的角色进行适当验证。这使得已认证的攻击者能够直接向 端点提供管理员的用户 ID,从而无需输入管理员密码即可获取完整的管理员会话 Cookie。因此,已认证的攻击者可以直接接管会话,获得对网站完全的管理员级别访问权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wpclever | WPC Shop as a Customer for WooCommerce | 0 ~ 2.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet