HackTips.

页面数据均来自于CVE官方,仅调用Api进行查询

1@1042.net

CVE编号CVE-2025-1508
发布日期2025-03-12T03:21:27.735Z
更新日期2025-03-12T13:31:16.173Z
状态PUBLISHED
受影响的供应商themeum
受影响的产品WP Crowdfunding
描述The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the download_data action in all versions up to, and including, 2.1.13. This makes it possible for authenticated attackers, with subscriber-level access and above, to download all of a site's post content when WooCommerce is installed.

参考链接:

Image Additional Image