Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-27qm-jwxp-8whw

Опубликовано: 21 нояб. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The WP-Polls WordPress plugin before 2.76.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitations to vote in certain situations.

The WP-Polls WordPress plugin before 2.76.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitations to vote in certain situations.

EPSS

Процентиль: 14%
0.00047
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 5.3
nvd
почти 3 года назад

The WP-Polls WordPress plugin before 2.76.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitations to vote in certain situations.

EPSS

Процентиль: 14%
0.00047
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-639