Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3qwq-8wfq-2pfc

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Countdown Block WordPress plugin before 1.1.2 does not have authorisation in the eb_write_block_css AJAX action, which allows any authenticated user, such as Subscriber, to modify post contents displayed to users.

The Countdown Block WordPress plugin before 1.1.2 does not have authorisation in the eb_write_block_css AJAX action, which allows any authenticated user, such as Subscriber, to modify post contents displayed to users.

EPSS

Процентиль: 38%
0.0017
Низкий

Дефекты

CWE-284
CWE-862

Связанные уязвимости

CVSS3: 4.3
nvd
больше 4 лет назад

The Countdown Block WordPress plugin before 1.1.2 does not have authorisation in the eb_write_block_css AJAX action, which allows any authenticated user, such as Subscriber, to modify post contents displayed to users.

EPSS

Процентиль: 38%
0.0017
Низкий

Дефекты

CWE-284
CWE-862