WordPress 的 SiteOrigin Widgets Bundle 插件在 1.74.3 及之前所有版本中存在目录遍历漏洞。攻击者可以通过 get_instance_css 函数利用该漏洞。这使得具有贡献者及以上权限的已认证攻击者能够读取服务器上任意文件的内容,而这些文件可能包含敏感信息。该小部件通常的 update()/sanitize_field_input() 流程(用于拒绝非十六进制颜色值)被完全绕过,因为 [siteorigin_widget] 简码处理器直接对攻击者提供的已解码 JSON 实例调
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| gpriday | SiteOrigin Widgets Bundle | 0 ~ 1.74.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet