Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5523-p533-prfw

Опубликовано: 22 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

Insertion of Sensitive Information Into Sent Data vulnerability in Ideal Postcodes UK Address Postcode Validation allows Retrieve Embedded Sensitive Data. This issue affects UK Address Postcode Validation: from n/a through 3.9.2.

Insertion of Sensitive Information Into Sent Data vulnerability in Ideal Postcodes UK Address Postcode Validation allows Retrieve Embedded Sensitive Data. This issue affects UK Address Postcode Validation: from n/a through 3.9.2.

EPSS

Процентиль: 16%
0.0005
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-201

Связанные уязвимости

CVSS3: 5.3
nvd
5 месяцев назад

An Insertion of Sensitive Information into Sent Data vulnerability in the Ideal Postcodes UK Address Postcode Validation WordPress plugin exposes the API key, allowing unauthorized third parties to retrieve and reuse the key across any domain. Since API keys are unrestricted by default, with the “Allowed URLs” field left empty upon creation of API key this can lead to unauthorized use and depletion of API credits.Note: the vulnerability is assessed based on the default configuration.This issue affects UK Address Postcode Validation: from n/a through 3.9.2.

EPSS

Процентиль: 16%
0.0005
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-201