WordPress 插件 Datalogics Ecommerce Delivery – Datalogics 在所有版本(含 2.6.65 及之前)中存在授权绕过漏洞。原因在于该插件未正确验证用户是否被授权执行相关操作。这使得具有“订阅者”级别或更高权限的已认证攻击者能够: 使用商店存储的身份验证令牌,通过外部物流 API 创建和取消真实的发货订单; 修改任意 WooCommerce 订单的订单帖子元数据; 覆盖插件中存储的 API 令牌; 触发发送给客户的发货通知邮件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| datalogics | Datalogics Ecommerce Delivery – Datalogics | 0 ~ 2.6.65 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet