WordPress 插件“Woocommerce Partial Shipment”在 3.4 及更早版本中,通过 、 和 这些 AJAX 动作,存在授权缺失(Missing Authorization)漏洞。 具体原因在于: 文件中的 AJAX 处理函数(在第 60–62 行注册,分别在第 228、263 和 291 行实现)既缺少权限(capability)检查,也缺少 nonce 验证,且未对调用者是否拥有所提供的 的所有权进行校验。 这使得已登录的攻击者(具有 Subscriber 或更高权限)能够: 1.
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wpexpertshub | Partial Shipment for WooCommerce | 0 ~ 3.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet