The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including…
中危 CVSS 4.3
摘要
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve all ConvertKit form data configured by the site's manager account, exposing integration de…
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
数据来源
- NVD DATABASE
原始链接
- https://plugins.trac.wordpress.org/browser/automatorwp/tags/5.8.4/includes/scripts.php#L161
- https://plugins.trac.wordpress.org/browser/automatorwp/tags/5.8.4/integrations/convertkit/includes/ajax-functions.php#L16
- https://plugins.trac.wordpress.org/browser/automatorwp/tags/5.8.4/integrations/convertkit/includes/ajax-functions.php#L66
- https://plugins.trac.wordpress.org/browser/automatorwp/tags/5.8.4/integrations/convertkit/includes/ajax-functions.php#L96
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3656285%40automatorwp&new=3656285%40automatorwp
- https://www.wordfence.com/threat-intel/vulnerabilities/id/b0fd8e7b-1985-4265-8e15-5b3988bb0225?source=cve
时间线
- nvd_ingest NVD