Wordpress 2.6.6...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

<p>/wp-content/plugins/wysija-newsletters/helpers/back.php<br></p><pre class="">function verify_capability(){ if( isset( $_REQUEST['page'] ) &amp;&amp; substr( $_REQUEST['page'] ,0 ,7 ) == 'wysija_' ){ switch( $_REQUEST['page'] ){ case 'wysija_campaigns': $role_needed = 'wysija_newsletters'; break; case 'wysija_subscribers': $role_needed = 'wysija_subscribers'; break; case 'wysija_config': $role_needed = 'wysija_config'; break; case 'wysija_statistics': $role_needed = 'wysija_stats_dashboard'; break; default: $role_needed = 'switch_themes'; } if( current_user_can( $role_needed ) ){ return true; } else{ die( 'You are not allowed here.' ); } }else{ // this is not a wysija interface/action we can let it pass return true; } } </pre><p>在PHPS默认配置$_POST[‘page’]变量覆盖了$ _REQUEST‘page’]数组中的$_GET‘page’]变量。</p><p>该插件使用$_REQUEST来检查访问权限。由POST参数设置为 一些不以'wysija_“开头就可以绕过admin_Init的权限判断。</p><p>/wp-content/plugins/wysija-newsletters/controllers/back/campaigns.php</p><pre class="">function...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息