漏洞描述 WordPress和WordPress plugin都是WordPress基金会的产品。WordPress是一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。WordPress plugin是一个应用插件。 WordPress plugin WP Fusion Lite 3.42.10 版本及之前版本存在日志信息泄露漏洞,该漏洞源于存在信息泄露问题。
相关漏洞推荐 POC CVE-2022-0188: CMP WordPress < 4.0.19 - Broken Access Control POC wordpress-wp-env-exposure: WordPress Configuration wp-env - Exposure POC wp-wpstatistics-log: WordPress Plugin WP Statistics Error Log Disclosure POC coldfusion-cfide-dir-listing: Adobe ColdFusion CFIDE - Directory Listing POC wp-a3-lazy-load-top-fpd: WordPress a3 Lazy Load - Full Path Disclosure POC wp-breadcrumb-navxt-fpd: WordPress Breadcrumb NavXT - Full Path Disclosure POC wp-cf7-data-source-fpd: WordPress Data Source for Contact Form 7 - Full Path Disclosure POC wp-header-footer-elementor-fpd: WordPress Header Footer Elementor - Full Path Disclosure POC wp-easy-wp-smtp-log-exposure: WordPress Easy WP SMTP - Log Exposure WordPress Drag and Drop Multiple File Upload for WooCommerce dnd_codedropz_upload_wc 文件上传漏洞(CVE-2025-4403) WordPress Broken Link Notifier /wp-admin/admin-ajax.php blnotifier_blinks 服务器端请求伪造漏洞(CVE-2025-6851) POC CVE-2024-29137: WordPress Tourfic Plugin <= 2.11.7 - Cross-Site Scripting POC wordpress-meta-box-fpd: WordPress Meta Box - Full Path Disclosure