The Logo Slider and Showcase... CVE-2021-24742

4.0 AV AC AU C I A
发布: 2021-11-01
修订: 2024-11-21

The Logo Slider and Showcase WordPress plugin before 1.3.37 allows Editor users to update the plugin's settings via the rtWLSSettings AJAX action because it uses a nonce for authorisation instead of a capability check.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息