WordPress Plugin WP Support Plus...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 漏洞插件地址 https://wordpress.org/plugins/wp-support-plus-responsive-ticket-system/ ### 漏洞说明 你可以登录任何人的账号,无需知道密码。这个漏洞是由于错误的使用wp_set_auth_cookie()导致的。 文件:wp-support-plus-responsive-ticket-system\includes\admin\loginGuestFacebook.php ``` <?php if($_POST['email']=='') die(); $user_id = username_exists( $_POST['username'] ); if(!$user_id){ $user_id=email_exists($_POST['email']); if(!$user_id){ $random_password = wp_generate_password( $length=12, $include_standard_special_chars=false ); $user_id= wp_create_user( $_POST['username'], $random_password, $_POST['email'] ); $full_name=explode(' ', $_POST['name']); $firstName=(isset($full_name[0]))?$full_name[0]:''; $lastName=(isset($full_name[1]))?$full_name[1]:''; wp_update_user( array( 'ID' => $user_id, 'first_name'=>$firstName, 'last_name'=>$lastName, 'display_name' => $_POST['name'], 'role' => 'subscriber' ) ); } } $user_info = get_userdata($user_id); if ( !is_user_logged_in() ) { wp_set_current_user( $user_id, $user_info->user_login );...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息