Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2m82-vj3v-6q9q

Опубликовано: 01 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The Academist Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.6. This is due to the academist_membership_check_facebook_user() function not properly verifying a user's identity prior to authenticating them. This makes it possible for unauthenticated attackers to log in as any user, including site administrators.

The Academist Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.6. This is due to the academist_membership_check_facebook_user() function not properly verifying a user's identity prior to authenticating them. This makes it possible for unauthenticated attackers to log in as any user, including site administrators.

EPSS

Процентиль: 65%
0.00482
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-288

Связанные уязвимости

CVSS3: 9.8
nvd
11 месяцев назад

The Academist Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.6. This is due to the academist_membership_check_facebook_user() function not properly verifying a user's identity prior to authenticating them. This makes it possible for unauthenticated attackers to log in as any user, including site administrators.

EPSS

Процентиль: 65%
0.00482
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-288