Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4v7r-f8hg-362g

Опубликовано: 05 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

The Word Balloon WordPress plugin before 4.20.3 does not protect some of its actions against CSRF attacks, allowing an unauthenticated attacker to trick a logged in user to delete arbitrary avatars by clicking a link.

The Word Balloon WordPress plugin before 4.20.3 does not protect some of its actions against CSRF attacks, allowing an unauthenticated attacker to trick a logged in user to delete arbitrary avatars by clicking a link.

EPSS

Процентиль: 38%
0.00164
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 6.5
nvd
около 2 лет назад

The Word Balloon WordPress plugin before 4.20.3 does not protect some of its actions against CSRF attacks, allowing an unauthenticated attacker to trick a logged in user to delete arbitrary avatars by clicking a link.

EPSS

Процентиль: 38%
0.00164
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-352