Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-48rf-c53v-4537

Опубликовано: 12 дек. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

The Donation Button WordPress plugin through 4.0.0 does not properly check for privileges and nonce tokens in its "donation_button_twilio_send_test_sms" AJAX action, which may allow any users with an account on the affected site, like subscribers, to use the plugin's Twilio integration to send SMSes to arbitrary phone numbers.

The Donation Button WordPress plugin through 4.0.0 does not properly check for privileges and nonce tokens in its "donation_button_twilio_send_test_sms" AJAX action, which may allow any users with an account on the affected site, like subscribers, to use the plugin's Twilio integration to send SMSes to arbitrary phone numbers.

EPSS

Процентиль: 36%
0.00153
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 4.3
nvd
около 3 лет назад

The Donation Button WordPress plugin through 4.0.0 does not properly check for privileges and nonce tokens in its "donation_button_twilio_send_test_sms" AJAX action, which may allow any users with an account on the affected site, like subscribers, to use the plugin's Twilio integration to send SMSes to arbitrary phone numbers.

EPSS

Процентиль: 36%
0.00153
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862