Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4pfx-jfj6-q6ch

Опубликовано: 16 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5

Описание

The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on multiple user privilege/security functions provided in versions up to, and including 4.3.17. This makes it possible for low-privileged attackers, like subscribers, to perform restricted actions that would be otherwise locked to a administrative-level user.

The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on multiple user privilege/security functions provided in versions up to, and including 4.3.17. This makes it possible for low-privileged attackers, like subscribers, to perform restricted actions that would be otherwise locked to a administrative-level user.

EPSS

Процентиль: 49%
0.00261
Низкий

5 Medium

CVSS3

Дефекты

CWE-284
CWE-862

Связанные уязвимости

CVSS3: 5
nvd
больше 1 года назад

The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on multiple user privilege/security functions provided in versions up to, and including 4.3.17. This makes it possible for low-privileged attackers, like subscribers, to perform restricted actions that would be otherwise locked to a administrative-level user.

EPSS

Процентиль: 49%
0.00261
Низкий

5 Medium

CVSS3

Дефекты

CWE-284
CWE-862