Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3hwm-xx77-96rq

Опубликовано: 15 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 3.23.5 via the get_image_alt function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract either excerpt data or titles of private or password-protected posts.

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 3.23.5 via the get_image_alt function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract either excerpt data or titles of private or password-protected posts.

EPSS

Процентиль: 48%
0.00246
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 4.3
nvd
больше 1 года назад

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 3.23.5 via the get_image_alt function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract either excerpt data or titles of private or password-protected posts.

EPSS

Процентиль: 48%
0.00246
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200