漏洞名稱:wordpress WP_Image_Editor_Imagick 指令注入漏洞
在/wp-includes/media.php的_wp_image_editor_choose函數內部找到(大概在2898行):
- $implementations = apply_filters( 'wp_image_editors', array( 'WP_Image_Editor_Imagick' , 'WP_Image_Editor_GD' ) );
修改為
- $implementations = apply_filters( 'wp_image_editors', array( 'WP_Image_Editor_GD' ,'WP_Image_Editor_Imagick' ) );