CVE-2024-5326 Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX <= 4.1.2 - 缺少授权导致任意选项更新
描述
WordPress 的 Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX 插件在所有版本直至并包括 4.1.2 中,由于对 'postx_presets_callback' 函数缺少权限检查,存在未经授权修改数据的漏洞。这使得拥有 Contributor 级别及以上权限的认证攻击者能够更改受影响站点上的任意选项。此漏洞可用于启用新用户注册并将新用户的默认角色设置为管理员。
用户(Contributor 级别及以上)可以启用新用户注册并将新用户的默认角色设置为管理员。
PoC:
https://github.com/truonghuuphuc/CVE-2024-5326/assets/20487674/fca81a71-9812-4d0f-b48f-2db94e2c7347