漏洞情报聚合

CVE-2026-78562 - The Verdure Core plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.2. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included. - 漏洞详情

漏洞编号:CVE-2026-78562

风险等级:高危

漏洞来源:CVE

CVE 编号:CVE-2026-78562

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-98

发布/更新时间:2026-08-25 / 2026-08-27

漏洞描述

The Verdure Core plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.2. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

相关链接

相关漏洞

« 返回首页