CVE-2024-43919: YARPP <= 5.30.10 - Missing Authorization

CVE-2024-43919: YARPP <= 5.30.10 - Missing Authorization-渗透云记 - 专注于网络安全与技术分享
CVE-2024-43919: YARPP <= 5.30.10 - Missing Authorization
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2024-43919: YARPP <= 5.30.10 – Missing Authorization

漏洞描述

The YARPP Yet Another Related Posts Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in the ~/includes/yarpp_pro_set_display_types.php file in all versions up to, and including, 5.30.10. This makes it possible for unauthenticated attackers to set display types.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享