The WP Force SSL & HTTPS SSL... CVE-2024-5770

- AV AC AU C I A
发布: 2024-12-11
修订: 2024-12-11

The WP Force SSL & HTTPS SSL Redirect plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_save_setting' function in versions up to, and including, 1.66. This makes it possible for authenticated attackers, subscriber-level permissions and above, to update the plugin settings.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息