漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
User Registration & Membership < 5.2.3 - Unauthenticated Privilege Escalation via Unbound members_data Membership ID
Vulnerability Description
The User Registration & Membership WordPress plugin before 5.2.3 does not validate that the membership tier submitted during public registration is one of the tiers allowed by the registration form before assigning that tier's associated user role, allowing unauthenticated users to register into an arbitrary published membership tier and obtain its role — up to administrator when such a tier exists.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
WordPress User Registration & Membership 权限许可和访问控制问题漏洞
Vulnerability Description
WordPress User Registration & Membership是WordPress基金会的一个用户注册与会员管理软件。 WordPress User Registration & Membership 5.2.3之前版本存在权限许可和访问控制问题漏洞,该漏洞源于未验证注册过程中提交的会员等级是否为表单允许的级别,可能导致未经验证的用户任意注册并获取管理员角色。
CVSS Information
N/A
Vulnerability Type
N/A