Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4878-3496-cr5j

Опубликовано: 25 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

The aoa-downloadable WordPress plugin through 0.1.0 lacks authorization and authentication for requests to its download.php endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.

The aoa-downloadable WordPress plugin through 0.1.0 lacks authorization and authentication for requests to its download.php endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.

EPSS

Процентиль: 30%
0.0011
Низкий

7.2 High

CVSS3

Связанные уязвимости

CVSS3: 7.2
nvd
11 месяцев назад

The aoa-downloadable WordPress plugin through 0.1.0 lacks authorization and authentication for requests to its download.php endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.

EPSS

Процентиль: 30%
0.0011
Низкий

7.2 High

CVSS3