Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2c3v-6gcr-6f8h

Опубликовано: 15 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

The EazyDocs WordPress plugin before 2.3.6 does not have authorization and CSRF checks when handling documents and does not ensure that they are documents from the plugin, allowing unauthenticated users to delete arbitrary posts, as well as add and delete documents/sections.

The EazyDocs WordPress plugin before 2.3.6 does not have authorization and CSRF checks when handling documents and does not ensure that they are documents from the plugin, allowing unauthenticated users to delete arbitrary posts, as well as add and delete documents/sections.

EPSS

Процентиль: 27%
0.00095
Низкий

7.5 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 7.5
nvd
около 2 лет назад

The EazyDocs WordPress plugin before 2.3.6 does not have authorization and CSRF checks when handling documents and does not ensure that they are documents from the plugin, allowing unauthenticated users to delete arbitrary posts, as well as add and delete documents/sections.

EPSS

Процентиль: 27%
0.00095
Низкий

7.5 High

CVSS3

Дефекты

CWE-862