CVE-2024-2782: WordPress FluentForms <= 5.1.16 - Broken Access Control

CVE-2024-2782: WordPress FluentForms <= 5.1.16 - Broken Access Control-渗透云记 - 专注于网络安全与技术分享
CVE-2024-2782: WordPress FluentForms <= 5.1.16 - Broken Access Control
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2024-2782: WordPress FluentForms <= 5.1.16 – Broken Access Control

漏洞描述

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wp-json/fluentform/v1/global-settings REST API endpoint in all versions up to, and including, 5.1.16. This makes it possible for unauthenticated attackers to modify all of the plugin's settings.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享