WordPress WooCommerce 漏洞列表
共找到 4 个与 WordPress WooCommerce 相关的漏洞
📅 加载漏洞趋势中...
-
Wordpress WooCommerce Ultimate Gift Card /wp-admin/admin-ajax.php mwb_wgm_preview_mail 文件上传漏洞(CVE-2024-8425) 无POC
WooCommerce Ultimate Gift Card 是 WordPress 平台上的一款用于创建、销售和管理礼品卡的插件。该插件在 mwb_wgm_preview_mail 和 mwb_wgm_woocommerce_add_cart_item_data 函数中存在文件类型验证不足的安全缺陷,导致未授权攻击者可上传任意文件至服务器。此漏洞可能被利用实现远程代码执行,从而完全控制受影响网站。由于该漏洞利用门槛低且危害严重,建议所有使用该插件的网站立即升级至最新版本。 -
CVE-2022-1020: WordPress WooCommerce <3.1.2 - Arbitrary Function Call POC
WordPress WooCommerce plugin before 3.1.2 does not have authorisation and CSRF checks in the wpt_admin_update_notice_option AJAX action (available to both unauthenticated and authenticated users), as well as does not validate the callback parameter, allowing unauthenticated attackers to call arbitrary functions with either none or one user controlled argument. fofa title="WordPress WooCommerce " -
CVE-2021-24300: WordPress WooCommerce <1.13.22 - Cross-Site Scripting POC
WordPress WooCommerce before 1.13.22 contains a reflected cross-site scripting vulnerability via the slider import search feature because it does not properly sanitize the keyword GET parameter. -
CVE-2022-1020: WordPress WooCommerce <3.1.2 - Arbitrary Function Call POC
WordPress WooCommerce plugin before 3.1.2 does not have authorisation and CSRF checks in the wpt_admin_update_notice_option AJAX action (available to both unauthenticated and authenticated users), as well as does not validate the callback parameter, allowing unauthenticated attackers to call arbitrary functions with either none or one user controlled argument.