CVE-2025-34077: WordPress Pie Register <= 3.7.1.4 - Authentication Bypass

CVE-2025-34077: WordPress Pie Register <= 3.7.1.4 - Authentication Bypass-渗透云记 - 专注于网络安全与技术分享
CVE-2025-34077: WordPress Pie Register <= 3.7.1.4 - Authentication Bypass
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2025-34077: wordpress Pie Register <= 3.7.1.4 – Authentication Bypass

漏洞描述

An authentication bypass vulnerability exists in the WordPress Pie Register plugin ≤ 3.7.1.4 that allows unauthenticated attackers to impersonate arbitrary users by submitting a crafted POST request to the login endpoint. By setting social_site=true and manipulating the user_id_social_site parameter, an attacker can generate a valid WordPress session cookie for any user ID, including administrators.Once authenticated, the attacker may exploit plugin upload functionality to install a malicious plugin containing arbitrary PHP code, resulting in remote code execution on the underlying server.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享