从这个网页截图中,可以获取到以下关于漏洞的关键信息: 1. 漏洞名称: - Request a Quote for WooCommerce and Elementor - Get a Quote Button - Product Enquiry Form Popup - Product Quotation <= 1.4 - Unauthenticated Arbitrary Shortcode Execution via fire_contact_form 2. 漏洞类型: - Improper Control of Generation of Code (Code Injection) 3. CVSS评分: - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L 4. CVE编号: - CVE-2024-11034 5. CVSS评分(高): - 7.3 6. 公开发布日期: - November 22, 2024 7. 最后更新日期: - November 23, 2024 8. 研究者: - Arkadiusz Hydzik 9. 受影响版本: - <= 1.4 10. 已修复: - Yes 11. 修复建议: - Update to version 1.5, or a newer patched version 12. 参考链接: - plugins.trac.wordpress.org - wordpress.org - plugins.trac.wordpress.org 13. 漏洞描述: - The Request a Quote for WooCommerce and Elementor - Get a Quote Button - Product Enquiry Form Popup - Product Quotation plugin for WordPress is vulnerable to arbitrary shortcode execution via fire_contact_form AJAX action in all versions up to, and including, 1.4. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. 14. 漏洞细节: - Software Type: Plugin - Software Slug: get-a-quote-button-for-woocommerce - Patched?: Yes - Remediation: Update to version 1.5, or a newer patched version - Affected Version: <= 1.4 - Patched Version: 1.5 15. 版权和许可信息: - Copyright 2012-2024 Defiant Inc. - Copyright 1999-2024 The MITRE Corporation 16. 联系方式: - wfi-support@wordfence.com 这些信息可以帮助用户了解漏洞的详细情况,包括其影响范围、修复建议以及如何获取更多信息。