WordPress ¶à¸ö²å¼þ¸ßΣ·ì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2020-02-19

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ThemeGrill Demo Importer  1.3.4 - 1.6.1

GDPR Cookie Consent < 1.8.2


·ì϶¸ÅÊö


WordPressÊÇWordPress»ù½ð»áµÄÒ»Ì×ʹÓÃPHP˵»°¿ª·¢µÄ²©¿Íƽ̨¡£¡£¡£¡£ ¡£¡£¡£¸Ãƽ̨֧³ÖÔÚPHPºÍMySQLµÄ·þÎñÆ÷ÉϼÜÉèÓ×ÎÒ²©¿ÍÍøÕ¾¡£¡£¡£¡£ ¡£¡£¡£


WordPress ThemeGrill Demo ImporterÊÇThemeGrill¿ª·¢µÄÑÝʾµ¼ÈëÆ÷£¬£¬£¬£¬£¬£¬£¬¸Ã²å¼þ¸½´øThemeGrillÏúÊÛµÄÖ÷Ì⣬£¬£¬£¬£¬£¬£¬ThemeGrillÊÇÒ»¼ÒÏúÊÛóÒ×WordPressÖ÷ÌâµÄweb¿ª·¢¹«Ë¾¡£¡£¡£¡£ ¡£¡£¡£Õâ¸ö²å¼þ×°ÖÃÔÚ20¶àÍò¸öÍøÕ¾ÉÏ£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÍøÕ¾ËùÓÐÕß½«ÑÝʾÄÚÈݵ¼ÈëËûÃǵÄThemeGrillÖ÷ÌâÖУ¬£¬£¬£¬£¬£¬£¬ÕâÑùËûÃǾÍÓÐÁËʾÀýºÍÒ»¸öÆðµã£¬£¬£¬£¬£¬£¬£¬Äܹ»ÔÚ´Ë»ù´¡ÉϹ¹½¨×Ô¼ºµÄÍøÕ¾¡£¡£¡£¡£ ¡£¡£¡£


WordPress ThemeGrill Demo Importer plugin ´æÔÚÒ»¸öȨÏÞÈÆ¹ý·ì϶£¬£¬£¬£¬£¬£¬£¬Ò»µ©¸Ã²å¼þ¼ì²âµ½Õ¾µã×°ÖÃÇÒ¼¤»îÁËThemeGrillÖ÷Ì⣬£¬£¬£¬£¬£¬£¬¾Í»á¼ÓÔØ/includes/class-demo-importer.phpÎļþ£¬£¬£¬£¬£¬£¬£¬¸ÃÎļþ½«reset_wizard_actionsº¯ÊýÒýÈëλÓÚµÚ44ÐеÄadmin_initº¯Êý¡£¡£¡£¡£ ¡£¡£¡£×êÑÐÈËÔ±Ú¹Ê͵½£¬£¬£¬£¬£¬£¬£¬admin_initº¯ÊýÔÚÖÎÀíÔ±»·¾³ÖÐÔËÐУ¬£¬£¬£¬£¬£¬£¬²¢ÇÒŲÓò»ÒªÇóÓû§Éí·ÝÈÏÖ¤µÄ/wp-admin/admin-ajax.phpÎļþ¡£¡£¡£¡£ ¡£¡£¡£¶ÌȱÉí·ÝÈÏÖ¤Ôì³É¿ÉÄܵķì϶ÀûÓᣡ£¡£¡£ ¡£¡£¡£ÈôÊÇÊý¾Ý¿âÖдæÔÚ¡°admin¡±Óû§£¬£¬£¬£¬£¬£¬£¬Î´¾­Éí·ÝÈÏÖ¤µÄ¹¥»÷Õß¿ÉÀûÓø÷ì϶µÇ¼Êý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬É¾³ýËùÓÐÒÔÃ÷È·µÄÊý¾Ý¿âǰ׺¿ªÍ·µÄWordPress±íµ¥¡£¡£¡£¡£ ¡£¡£¡£Ò»µ©É¾³ýËùÓÐµÄ±íµ¥ºó£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õ߾ͻáÁ¢¼´ÒÔĬÈÏÉèÖúÍÊý¾ÝÌî³äÊý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬½ÓמͻὫ¡°admin¡±Óû§µÄÃÜÂëÉèÖóɹ¥»÷ÕßÒÑÖªµÄÃÜÂë¡£¡£¡£¡£ ¡£¡£¡£


WordPress GDPR Cookie Consent ÊÇÊ¹ÍøÕ¾ÇкÏGDPR»®¶¨µÄÒ»¸ö²å¼þ£¬£¬£¬£¬£¬£¬£¬ÍøÕ¾ÖÎÀíÔ±Äܹ»ÀûÓÃGDPR Cookie Consent²å¼þ£¬£¬£¬£¬£¬£¬£¬À´Õ¹Ê¾×Ô½ç˵µÄҳüºÍÒ³½Åcookieºá·ù£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚÏÔÊ¾ÍøÕ¾ÇкÏÅ·ÃËcookieÂÉÀý£¨GDPR£©»®¶¨¡£¡£¡£¡£ ¡£¡£¡£¸Ã²å¼þÓÉWebToffee¹«Ë¾ÊØ»¤£¬£¬£¬£¬£¬£¬£¬ÊÇWordPress²å¼þ¿âÖÐ×îÊ¢ÐеÄ100¸ö²å¼þÖ®Ò»£¬£¬£¬£¬£¬£¬£¬³¬¹ý70Íò¸öÍøÕ¾Ê¹ÓÃÁ˸òå¼þ¡£¡£¡£¡£ ¡£¡£¡£


WordPress GDPR Cookie Consent plugin ´æÔÚÒ»¸ö´æ´¢ÐÍXSS·ì϶£¬£¬£¬£¬£¬£¬£¬¾­Éí·ÝÈÏÖ¤µÄÓû§£¬£¬£¬£¬£¬£¬£¬ÀýÈç¶©ÔÄÓû§£¬£¬£¬£¬£¬£¬£¬Äܹ»Í¨¹ý½«ÏÖÓеÄÒ³Ãæ»òÎÄÕ£¨ÉõÖÁÕû¸öÍøÕ¾£©µÄ״̬´Ó¡°ÒѰ䲼¡±¸ÄΪ¡°²Ý¸å¡±ÀûÓø÷ì϶ÏÂÏßÒ³Ãæ¡¢ÎÄÕÂÉõÖÁÕû¸öÍøÕ¾¡£¡£¡£¡£ ¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß»¹Äܹ»É¾³ý»òÅú¸ÄÄÚÈÝ¡£¡£¡£¡£ ¡£¡£¡£×¢ÈëµÄÄÚÈÝÄܹ»Ô̺¬Ìåʽ»¯Îı¾¡¢±¾µØ»òÔ¶³ÌͼÏñÒÔ¼°³¬Á´½ÓºÍ¶Ì´úÂë¡£¡£¡£¡£ ¡£¡£¡£¹¥»÷Õß»¹Äܹ»ÀûÓø÷ì϶עÈëJavaScript´úÂ룬£¬£¬£¬£¬£¬£¬µ±Óû§½Ó¼û/cli-policy-preview/Ò³ÃæÊ±£¬£¬£¬£¬£¬£¬£¬×¢ÈëµÄ´úÂë¾Í»á×Ô¶¯¼ÓÔØÖ´ÐÓ×£¡£¡£¡£ ¡£¡£¡£¸Ã·ì϶ԴÓÚcli_policy_generator AJAXŲÓú¯ÊýÖдæÔÚÒ»¸ö½Ó¼û½ÚÔì²»µ±ÎÊÌ⣬£¬£¬£¬£¬£¬£¬½«get_policy_pageid£¬£¬£¬£¬£¬£¬£¬autosave_contant_dataºÍsave_contentdata²Ù×÷¶³ö¸ø¶©ÔÄÓû§¡£¡£¡£¡£ ¡£¡£¡£


·ì϶ÑéÖ¤


ÔÝÎÞPoC/EXP¡£¡£¡£¡£ ¡£¡£¡£


½¨¸´½¨Òé


ThemeGrill Demo Importer¹Ù·½°ä²¼µÄ×îа汾1.6.2ÒѾ­½¨¸´ÁË´Ë·ì϶£¬£¬£¬£¬£¬£¬£¬ÇëÊÜÓ°ÏìµÄÓû§ÏÂÔØ×îа汾·ÀÓù´Ë·ì϶¡£¡£¡£¡£ ¡£¡£¡£ÏÂÔØÁ´½Ó£ºhttps://cn.wordpress.org/plugins/themegrill-demo-importer/advanced/¡£¡£¡£¡£ ¡£¡£¡£


GDPR Cookie Consent¹Ù·½°ä²¼µÄ×îа汾1.8.3ÒѾ­½¨¸´ÁË´Ë·ì϶£¬£¬£¬£¬£¬£¬£¬ÇëÊÜÓ°ÏìµÄÓû§ÏÂÔØ×îа汾·ÀÓù´Ë·ì϶¡£¡£¡£¡£ ¡£¡£¡£ÏÂÔØÁ´½Ó£ºhttps://wordpress.org/plugins/cookie-law-info/¡£¡£¡£¡£ ¡£¡£¡£


²Î¿¼Á´½Ó


https://www.zdnet.com/article/bug-in-wordpress-plugin-can-let-hackers-wipe-up-to-200000-sites/#ftag=RSSbaffb68