标题:WordPress plugin 安全漏洞
(CVE-2021-24278) Description:WordPress是Wordpress基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。WordPress 插件是WordPress开源的一个应用插件。 Contact Form 7 WordPress plugin 2.3.4之前版本存在安全漏洞,该漏洞允许未经过身份验证的用户可以使用wpcf7r get nonce AJAX动作来检索任何WordPress动作函数的有效nonce。
Description
WordPress Contact Form 7 before version 2.3.4 allows unauthenticated users to use the wpcf7r_get_nonce AJAX action to retrieve a valid nonce for any WordPress action/function.