Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4mq9-mp5g-r83q

Опубликовано: 16 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to Arbitrary File Read and Delete due to a lack of input parameter validation in the gallery_edit function, allowing an attacker to access arbitrary resources on the server.

The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to Arbitrary File Read and Delete due to a lack of input parameter validation in the gallery_edit function, allowing an attacker to access arbitrary resources on the server.

EPSS

Процентиль: 56%
0.00342
Низкий

7.2 High

CVSS3

Дефекты

CWE-552

Связанные уязвимости

CVSS3: 7.2
nvd
больше 2 лет назад

The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to Arbitrary File Read and Delete due to a lack of input parameter validation in the `gallery_edit` function, allowing an attacker to access arbitrary resources on the server.

EPSS

Процентиль: 56%
0.00342
Низкий

7.2 High

CVSS3

Дефекты

CWE-552