WordPress Custom-contact-forms...

- AV AC AU C I A
发布: 2024-08-31
修订: 2025-04-13

The WordPress custom-contact-forms plugin less than or equal to 5.1.0.3 allows unauthenticated users to download a SQL dump of the plugins database tables. Its also possible to upload files containing SQL statements which will be executed. The module first tries to extract the WordPress table prefix from the dump and then attempts to create a new admin user.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息