Description
Auto Amazon Links – Amazon Associates Affiliate Plugin 插件在 WordPress 5.4.3 及以下版本中,存在任意文件读取漏洞。攻击者可通过访问 '/wp-json/wp/v2/aal_ajax_unit_loading' REST API 接口,在未经身份验证的情况下读取服务器上的任意文件。这些文件可能包含敏感信息,如数据库凭证、配置文件等,严重威胁系统的安全。
Auto Amazon Links – Amazon Associates Affiliate Plugin 插件在 WordPress 5.4.3 及以下版本中,存在任意文件读取漏洞。攻击者可通过访问 '/wp-json/wp/v2/aal_ajax_unit_loading' REST API 接口,在未经身份验证的情况下读取服务器上的任意文件。这些文件可能包含敏感信息,如数据库凭证、配置文件等,严重威胁系统的安全。
None yet. Search at https://trap.biu.life/?ref=rss