POC详情: e3d2c4281b34eb7cf57c47894dd8cab33b8d661b

来源
关联漏洞
标题: WordPress 安全漏洞 (CVE-2020-36155)
描述:WordPress是WordPress(Wordpress)基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。Ultimate Member plugin是使用在其中的一款用于创建会员网站或在线社区的插件。 Ultimate Member plugin before 2.1.12 for WordPress 存在安全漏洞,攻击者可利用该漏洞可以为敏感元数据提供数组参数。
描述
An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Meta. An attacker could supply an array parameter for sensitive metadata, such as the wp_capabilities user meta that defines a user's role. During the registration process, submitted registration details were passed to the update_profile function, and any metadata was accepted, e.g., wp_capabilities[administrator] for Administrator access.
文件快照

id: CVE-2020-36155 info: name: Ultimate Member < 2.1.12 - Unauthenticated Privilege Escalation vi ...
神龙机器人已为您缓存
备注
    1. 建议优先通过来源进行访问。
    2. 如果因为来源失效或无法访问,请发送邮箱到 f.jinxu#gmail.com 索取本地快照(把 # 换成 @)。
    3. 神龙已为您对POC代码进行快照,为了长期维护,请考虑为本地POC付费,感谢您的支持。