CVE-2025-3605: WordPress Frontend Login and Registration Blocks Plugin 1.0.7 – Privilege Escalation

CVE-2025-3605: WordPress Frontend Login and Registration Blocks Plugin 1.0.7 - Privilege Escalation-渗透云记 - 专注于网络安全与技术分享
CVE-2025-3605: WordPress Frontend Login and Registration Blocks Plugin 1.0.7 – Privilege Escalation
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2025-3605: wordpress Frontend Login and Registration Blocks Plugin 1.0.7 – Privilege Escalation

漏洞描述

Privilege escalation vulnerability exists in the Frontend Login and Registration Blocks plugin for WordPress (versions <= 1.0.7). An unauthenticated attacker can exploit the AJAX endpoint flr_blocks_user_settings_handle_ajax_callback() to change the administrator's email address. Subsequently, the attacker can use the "Forgot Password" feature to reset the administrator's password, thereby gaining unauthorized access to the admin account.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享