Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3hq2-mp89-6vp5

Опубликовано: 22 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token to be verified before matching it to a WordPress account and issuing a session, allowing unauthenticated attackers to log in as any user, including administrators.

The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token to be verified before matching it to a WordPress account and issuing a session, allowing unauthenticated attackers to log in as any user, including administrators.

EPSS

Процентиль: 11%
0.00204
Низкий

8.1 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

nvd
3 дня назад

The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token to be verified before matching it to a WordPress account and issuing a session, allowing unauthenticated attackers to log in as any user, including administrators.

EPSS

Процентиль: 11%
0.00204
Низкий

8.1 High

CVSS3

Дефекты

CWE-287