WordPress 的 Simple Membership 插件在 4.8.3 及更早版本中,存在未经授权的数据修改和敏感信息泄露漏洞,该漏洞通过 resend-activation 和 email-activation 接口触发。这些接口在 WordPress 前端初始化过程中由 SwpmInitTimeTasks::check_and_do_email_activation() 函数执行,无需进行任何身份验证、nonce 校验、权限检查或所有权验证。同时,SwpmRegistration::send_reg_e
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| wpinsider-1 | Simple Membership | ≤ 4.8.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wpinsider-1 | Simple Membership | 0 ~ 4.8.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet