HackTips.

页面数据均来自于CVE官方,仅调用Api进行查询

1@1042.net

CVE编号CVE-2025-0177
发布日期2025-03-08T08:22:57.176Z
更新日期2025-03-10T15:55:37.070Z
状态PUBLISHED
受影响的供应商javothemes
受影响的产品Javo Core
描述The Javo Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.0.0.080. This is due to the plugin allowing users who are registering new accounts to set their own role. This makes it possible for unauthenticated attackers to gain elevated privileges by creating an account with the administrator role.

参考链接:

Image Additional Image