WordPress ¶à¸ö²å¼þ¸ßΣÎó²îΣº¦Í¨¸æ
Ðû²¼Ê±¼ä 2020-02-19Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
ThemeGrill Demo Importer 1.3.4 - 1.6.1
GDPR Cookie Consent < 1.8.2
Îó²î¸ÅÊö
WordPressÊÇWordPress»ù½ð»áµÄÒ»Ì×ʹÓÃPHPÓïÑÔ¿ª·¢µÄ²©¿Íƽ̨¡£¡£¡£¡£¡£¡£¡£¸Ãƽ̨֧³ÖÔÚPHPºÍMySQLµÄЧÀÍÆ÷ÉϼÜÉèСÎÒ˽¼Ò²©¿ÍÍøÕ¾¡£¡£¡£¡£¡£¡£¡£
WordPress ThemeGrill Demo ImporterÊÇThemeGrill¿ª·¢µÄÑÝʾµ¼ÈëÆ÷£¬£¬£¬£¬£¬£¬£¬¸Ã²å¼þ¸½´øThemeGrill³öÊÛµÄÖ÷Ì⣬£¬£¬£¬£¬£¬£¬ThemeGrillÊÇÒ»¼Ò³öÊÛÉÌÒµWordPressÖ÷ÌâµÄweb¿ª·¢¹«Ë¾¡£¡£¡£¡£¡£¡£¡£Õâ¸ö²å¼þ×°ÖÃÔÚ20¶àÍò¸öÍøÕ¾ÉÏ£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÍøÕ¾ËùÓÐÕß½«ÑÝʾÄÚÈݵ¼ÈëËûÃǵÄThemeGrillÖ÷ÌâÖУ¬£¬£¬£¬£¬£¬£¬ÕâÑùËûÃǾÍÓÐÁËʾÀýºÍÒ»¸öÆðµã£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÔÚ´Ë»ù´¡ÉϹ¹½¨×Ô¼ºµÄÍøÕ¾¡£¡£¡£¡£¡£¡£¡£
WordPress ThemeGrill Demo Importer plugin ±£´æÒ»¸öȨÏÞÈÆ¹ýÎó²î£¬£¬£¬£¬£¬£¬£¬Ò»µ©¸Ã²å¼þ¼ì²âµ½Õ¾µã×°ÖÃÇÒ¼¤»îÁËThemeGrillÖ÷Ì⣬£¬£¬£¬£¬£¬£¬¾Í»á¼ÓÔØ/includes/class-demo-importer.phpÎļþ£¬£¬£¬£¬£¬£¬£¬¸ÃÎļþ½«reset_wizard_actionsº¯ÊýÒýÈëλÓÚµÚ44ÐеÄadmin_initº¯Êý¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±Ú¹Ê͵½£¬£¬£¬£¬£¬£¬£¬admin_initº¯ÊýÔÚÖÎÀíÔ±ÇéÐÎÖÐÔËÐУ¬£¬£¬£¬£¬£¬£¬²¢ÇÒŲÓò»ÒªÇóÓû§Éí·ÝÈÏÖ¤µÄ/wp-admin/admin-ajax.phpÎļþ¡£¡£¡£¡£¡£¡£¡£È±ÉÙÉí·ÝÈÏÖ¤Ôì³É¿ÉÄܵÄÎó²îʹÓᣡ£¡£¡£¡£¡£¡£ÈôÊÇÊý¾Ý¿âÖб£´æ¡°admin¡±Óû§£¬£¬£¬£¬£¬£¬£¬Î´¾Éí·ÝÈÏÖ¤µÄ¹¥»÷Õß¿ÉʹÓøÃÎó²îµÇ¼Êý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬É¾³ýËùÓÐÒÔÃ÷È·µÄÊý¾Ý¿âǰ׺¿ªÍ·µÄWordPress±íµ¥¡£¡£¡£¡£¡£¡£¡£Ò»µ©É¾³ýËùÓÐµÄ±íµ¥ºó£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õ߾ͻáÁ¬Ã¦ÒÔĬÈÏÉèÖúÍÊý¾ÝÌî³äÊý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬½ÓמͻὫ¡°admin¡±Óû§µÄÃÜÂëÉèÖóɹ¥»÷ÕßÒÑÖªµÄÃÜÂë¡£¡£¡£¡£¡£¡£¡£
WordPress GDPR Cookie Consent ÊÇÊ¹ÍøÕ¾ÇкÏGDPR»®¶¨µÄÒ»¸ö²å¼þ£¬£¬£¬£¬£¬£¬£¬ÍøÕ¾ÖÎÀíÔ±¿ÉÒÔʹÓÃGDPR Cookie Consent²å¼þ£¬£¬£¬£¬£¬£¬£¬À´Õ¹Ê¾×Ô½ç˵µÄҳüºÍÒ³½Åcookieºá·ù£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚÏÔÊ¾ÍøÕ¾ÇкÏÅ·ÃËcookie¹æÔò£¨GDPR£©»®¶¨¡£¡£¡£¡£¡£¡£¡£¸Ã²å¼þÓÉWebToffee¹«Ë¾Î¬»¤£¬£¬£¬£¬£¬£¬£¬ÊÇWordPress²å¼þ¿âÖÐ×îÊ¢ÐеÄ100¸ö²å¼þÖ®Ò»£¬£¬£¬£¬£¬£¬£¬Áè¼Ý70Íò¸öÍøÕ¾Ê¹ÓÃÁ˸òå¼þ¡£¡£¡£¡£¡£¡£¡£
WordPress GDPR Cookie Consent plugin ±£´æÒ»¸ö´æ´¢ÐÍXSSÎó²î£¬£¬£¬£¬£¬£¬£¬¾Éí·ÝÈÏÖ¤µÄÓû§£¬£¬£¬£¬£¬£¬£¬ÀýÈç¶©ÔÄÓû§£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ý½«ÏÖÓеÄÒ³Ãæ»òÎÄÕ£¨ÉõÖÁÕû¸öÍøÕ¾£©µÄ״̬´Ó¡°ÒÑÐû²¼¡±¸ÄΪ¡°µ×¸å¡±Ê¹ÓøÃÎó²îÏÂÏßÒ³Ãæ¡¢ÎÄÕÂÉõÖÁÕû¸öÍøÕ¾¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß»¹¿ÉÒÔɾ³ý»òÐÞ¸ÄÄÚÈÝ¡£¡£¡£¡£¡£¡£¡£×¢ÈëµÄÄÚÈÝ¿ÉÒÔ°üÀ¨ÃûÌû¯Îı¾¡¢ÍâµØ»òÔ¶³ÌͼÏñÒÔ¼°³¬Á´½ÓºÍ¶Ì´úÂë¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß»¹¿ÉÒÔʹÓøÃÎó²î×¢ÈëJavaScript´úÂ룬£¬£¬£¬£¬£¬£¬µ±Óû§»á¼û/cli-policy-preview/Ò³ÃæÊ±£¬£¬£¬£¬£¬£¬£¬×¢ÈëµÄ´úÂë¾Í»á×Ô¶¯¼ÓÔØÖ´ÐС£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚcli_policy_generator AJAXŲÓú¯ÊýÖб£´æÒ»¸ö»á¼û¿ØÖƲ»µ±ÎÊÌ⣬£¬£¬£¬£¬£¬£¬½«get_policy_pageid£¬£¬£¬£¬£¬£¬£¬autosave_contant_dataºÍsave_contentdata²Ù×÷̻¶¸ø¶©ÔÄÓû§¡£¡£¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
ÔÝÎÞPoC/EXP¡£¡£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
ThemeGrill Demo Importer¹Ù·½Ðû²¼µÄ×îа汾1.6.2ÒѾÐÞ¸´ÁË´ËÎó²î£¬£¬£¬£¬£¬£¬£¬ÇëÊÜÓ°ÏìµÄÓû§ÏÂÔØ×îа汾·ÀÓù´ËÎó²î¡£¡£¡£¡£¡£¡£¡£ÏÂÔØÁ´½Ó£ºhttps://cn.wordpress.org/plugins/themegrill-demo-importer/advanced/¡£¡£¡£¡£¡£¡£¡£
GDPR Cookie Consent¹Ù·½Ðû²¼µÄ×îа汾1.8.3ÒѾÐÞ¸´ÁË´ËÎó²î£¬£¬£¬£¬£¬£¬£¬ÇëÊÜÓ°ÏìµÄÓû§ÏÂÔØ×îа汾·ÀÓù´ËÎó²î¡£¡£¡£¡£¡£¡£¡£ÏÂÔØÁ´½Ó£ºhttps://wordpress.org/plugins/cookie-law-info/¡£¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://www.zdnet.com/article/bug-in-wordpress-plugin-can-let-hackers-wipe-up-to-200000-sites/#ftag=RSSbaffb68


¾©¹«Íø°²±¸11010802024551ºÅ