Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-13700 PoC — WordPress acf-to-rest-api 信息泄露漏洞

Source
Associated Vulnerability
Title:WordPress acf-to-rest-api 信息泄露漏洞 (CVE-2020-13700)
Description:WordPress是WordPress(Wordpress)基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。 WordPress acf-to-rest-api 3.1.0及之前版本中存在安全漏洞。攻击者可利用该漏洞读取wp_options表中的敏感信息。
Description
WordPresss acf-to-rest-ap through 3.1.0 allows an insecure direct object reference via permalinks manipulation, as demonstrated by a wp-json/acf/v3/options/ request that can read sensitive information in the wp_options table such as the login and pass values.
File Snapshot

id: CVE-2020-13700 info: name: WordPresss acf-to-rest-api <=3.1.0 - Insecure Direct Object Refere ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.