Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-43504

Опубликовано: 05 дек. 2022
Источник: debian
EPSS Низкий

Описание

Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of the user who posted a blog using the WordPress Post by Email Feature. The developer also provides new patched releases for all versions since 3.7.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
wordpressfixed6.0.3+dfsg1-1package
wordpressfixed5.0.18+dfsg1-0+deb10u1busterpackage

Примечания

  • https://wordpress.org/news/2022/10/wordpress-6-0-3-security-release/

  • Fixed by: https://core.trac.wordpress.org/changeset/54531 (6.0)

  • Follow-up: https://core.trac.wordpress.org/changeset/54533 (6.0)

EPSS

Процентиль: 80%
0.0154
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 2 лет назад

Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of the user who posted a blog using the WordPress Post by Email Feature. The developer also provides new patched releases for all versions since 3.7.

CVSS3: 5.3
nvd
больше 2 лет назад

Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of the user who posted a blog using the WordPress Post by Email Feature. The developer also provides new patched releases for all versions since 3.7.

CVSS3: 5.3
github
больше 2 лет назад

Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of the user who posted a blog using the WordPress Post by Email Feature.

EPSS

Процентиль: 80%
0.0154
Низкий