Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2c8q-6gj7-g33w

Опубликовано: 07 июн. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

The Ultimate Addons for Gutenberg plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 1.14.7. This is due to missing capability checks on several AJAX actions. This makes it possible for authenticated attackers with subscriber+ roles to update the plugin's settings.

The Ultimate Addons for Gutenberg plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 1.14.7. This is due to missing capability checks on several AJAX actions. This makes it possible for authenticated attackers with subscriber+ roles to update the plugin's settings.

EPSS

Процентиль: 11%
0.00037
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 5.5
nvd
больше 2 лет назад

The Ultimate Addons for Gutenberg plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 1.14.7. This is due to missing capability checks on several AJAX actions. This makes it possible for authenticated attackers with subscriber+ roles to update the plugin's settings.

EPSS

Процентиль: 11%
0.00037
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-862