漏洞描述 WordPress是Wordpress基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。WordPressTI WooCommerce Wishlist plugin1.40.1之前版本存在SQL注入漏洞,该漏洞源于插件在通过wishlist/remove_productREST端点在SQL语句中使用之前未能清理和转义item_id参数,未经身份验证的攻击者可利用该漏洞执行非法SQL命令窃取数据库敏感数据。
相关漏洞推荐 POC CVE-2017-14725: WordPress < 4.8.2 - Authenticated Open Redirect POC CVE-2017-17092: WordPress < 4.9.1 - Authenticated JavaScript File Upload POC wp-security-hidden-login-exposure: WordPress All-in-One Security <=4.4.1 - Hidden Login Page Exposure AstrBot /api/plugin/install-upload 命令执行漏洞(CVE-2025-55449) WordPress Kognetiks Chatbot for WordPress <= 2.0.0 任意文件上传漏洞 WordPress Verbalize WP 存在任意文件上传漏洞(CVE-2024-49668) POC CVE-2021-4374: WordPress Automatic Plugin - Unauthenticated Options Change POC CVE-2025-11749: WordPress AI Engine Plugin - Token Exposure WordPress WooCommerce Designer Pro 插件 /wp-admin/admin-ajax.php wcdp_save_canvas_design_ajax 文件上传漏洞(CVE-2025-6440) POC CVE-2025-4302: Stop User Enumeration WordPress plugin - Authentication Bypass WordPress Google for WooCommerce /wp-content/plugins/google-listings-and-ads/vendor/googleads/google-ads-php/scripts/print_php_information.php 信息泄露漏洞(CVE-2024-10486) WordPress Events Manager /wp-admin/admin-ajax.php SQL 注入漏洞(CVE-2025-6970) Trinity Audio /wp-content/plugins/trinity-audio/admin/inc/phpinfo.php 信息泄露漏洞(CVE-2025-9196)