漏洞描述 MetformWordPress插件易受敏感信息泄露的影响,在2.1.3之前的版本中,对SQL/core/forms/action.php文件的访问控制不当,未经身份验证的攻击者可利用该文件查看所有API密钥和集成的第三方API(如PayPal、Stripe、Mailchimp、Hubspot、HelpScout、reCAPTCHA等信息。
相关漏洞推荐 POC CVE-2016-15041: MainWP Dashboard <= 3.1.2 - Stored Cross-Site Scripting POC CVE-2018-7765: Schneider Electric U.motion Builder - SQL Injection POC CVE-2019-12935: Shopware < 5.5.8 - Cross-Site Scripting POC CVE-2019-14206: Nevma Adaptive Images - Arbitrary File Deletion POC CVE-2020-19363: Vtiger CRM v7.2.0 - Directory Listing POC CVE-2020-9039: Couchbase Server - Broken Access Control POC CVE-2021-28799: QNAP HBS 3 - Broken Access Control POC CVE-2021-37598: WP Cerber < 8.9.3 - Broken Access Control POC CVE-2022-37932: HP Switch - Authentication Bypass POC CVE-2023-33960: OpenProject < 12.5.4 - Project Identifiers Exposure POC CVE-2023-52163: Digiever DS-2105 Pro - Command Injection POC CVE-2024-29137: WordPress Tourfic Plugin <= 2.11.7 - Cross-Site Scripting POC CVE-2024-29792: Unlimited Elements for Elementor <= 1.5.93 - Cross Site Scripting