Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2qv2-8rj8-m28p

Опубликовано: 05 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

The DesignThemes Core Features plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the dt_process_imported_file function in all versions up to, and including, 4.7. This makes it possible for unauthenticated attackers to read arbitrary files on the underlying operating system.

The DesignThemes Core Features plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the dt_process_imported_file function in all versions up to, and including, 4.7. This makes it possible for unauthenticated attackers to read arbitrary files on the underlying operating system.

EPSS

Процентиль: 81%
0.01533
Низкий

7.5 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
nvd
11 месяцев назад

The DesignThemes Core Features plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the dt_process_imported_file function in all versions up to, and including, 4.7. This makes it possible for unauthenticated attackers to read arbitrary files on the underlying operating system.

EPSS

Процентиль: 81%
0.01533
Низкий

7.5 High

CVSS3

Дефекты

CWE-22