Transposh WordPress Translation...

- AV AC AU C I A
发布: 2022-07-29
修订: 2024-12-11

Transposh WordPress Translation versions 1.0.8.1 and below have an ajax action called "tp_history" which is intended to return data about who has translated a text given by the "token" parameter. However, the plugin also returns the user's login name as part of the "user_login" attribute. Successful exploits can allow an unauthenticated attacker to leak the WordPress username of translators. If an anonymous user submitted the translation, then the user's IP address is returned.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息