漏洞标题
WP All Export Pro <= 1.9.1 - 经认证(ShopManager+)任意选项更新漏洞
漏洞描述信息
针对 WordPress 的 WP ALL Export Pro 插件在所有版本(包括)1.9.1 中,由于对用户输入验证和过滤不当,存在未经授权的数据修改漏洞,可能导致权限提升。此漏洞使得具有 Shop Manager 级别及以上访问权限的经过身份验证的攻击者能够更新 WordPress 站点上的任意选项。攻击者可以利用此漏洞将注册用户的默认角色设置为管理员,并启用用户注册功能,从而获取易受攻击站点的管理员访问权限。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
漏洞类别
输入验证不恰当
漏洞标题
WP All Export Pro <= 1.9.1 - Authenticated (ShopManager+) Arbtirary Options Update
漏洞描述信息
The WP ALL Export Pro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to improper user input validation and sanitization in all versions up to, and including, 1.9.1. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
漏洞类别
对生成代码的控制不恰当(代码注入)