在查看更多的插件和主题后,发现了2个主题和更多的插件存在Freemius Library 未更新的情况,从而导致了低权限用户可以任意更改网站配置
after i looked into more plugins,i found the same vulnerability for other plugins and they are available for download
Affiliate Link Builder Plugin for Amazon Associates – Review Engine
以下是两个主题信息
在提交wpscan和wordpress团队后,他们及时更新了安全漏洞信息
关于这个安全漏洞更多的信息, https://wpscan.com/vulnerability/6ff37c2e-e21d-4abc-bafe-8ca6a2c1ed76