WordPress 平台的 Empik for WooCommerce 插件在 1.5.1 及之前所有版本中均存在授权绕过漏洞。该漏洞源于插件未能正确验证用户是否有权执行特定操作。这导致拥有订阅者级别或更高权限的已认证攻击者,可以修改商店中任意 WooCommerce 产品的元数据,包括 Empik 物流类别(_empik_logistic_klass)、产品状态(_empik_product_state、_empik_product_state_all_variants)以及 Empik 的导出和报价标志。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| empik | Empik for Woocommerce | 0 ~ 1.5.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet