The WP eCommerce plugin for... CVE-2024-1516

- AV AC AU C I A
发布: 2024-02-28
修订: 2025-02-11

The WP eCommerce plugin for WordPress is vulnerable to unauthorized arbitrary post creation due to a missing capability check on the check_for_saas_push() function in all versions up to, and including, 3.15.1. This makes it possible for unauthenticated attackers to create arbitrary posts with arbitrary content.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息