Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3jrv-ghj9-h744

Опубликовано: 11 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.2.5.7 via the get_content function. This is due to the plugin making use of the call_user_func function with user input. This makes it possible for unauthenticated attackers to execute any public function with one parameter, which could result in remote code execution.

The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.2.5.7 via the get_content function. This is due to the plugin making use of the call_user_func function with user input. This makes it possible for unauthenticated attackers to execute any public function with one parameter, which could result in remote code execution.

EPSS

Процентиль: 100%
0.91594
Критический

8.1 High

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 8.1
nvd
около 2 лет назад

The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.2.5.7 via the get_content function. This is due to the plugin making use of the call_user_func function with user input. This makes it possible for unauthenticated attackers to execute any public function with one parameter, which could result in remote code execution.

CVSS3: 8.1
fstec
около 2 лет назад

Уязвимость функции call_user_func плагина LearnPress системы управления содержимым сайта WordPress, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 100%
0.91594
Критический

8.1 High

CVSS3

Дефекты

CWE-77