CVE-2021-4374: WordPress Automatic Plugin – Unauthenticated Options Change

CVE-2021-4374: WordPress Automatic Plugin - Unauthenticated Options Change-渗透云记 - 专注于网络安全与技术分享
CVE-2021-4374: WordPress Automatic Plugin – Unauthenticated Options Change
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2021-4374: WordPress Automatic Plugin – Unauthenticated Options Change

漏洞描述

WordPress Automatic Plugin (versions 3.53.2 and below) contains a critical vulnerability that allows unauthenticated users to change arbitrary WordPress options through the process_form.php script. The vulnerable script uses update_option() on all POST parameters without authentication or capability checks, allowing attackers to create administrator accounts or modify critical settings. The vulnerability can be exploited even if the plugin is deactivated as it's a standalone script.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享