Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5fff-r5vh-5wpc

Опубликовано: 12 июл. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

The Admin Management Xtended WordPress plugin before 2.4.5 does not have CSRF checks in some of its AJAX actions, allowing attackers to make a logged users with the right capabilities to call them. This can lead to changes in post status (draft, published), slug, post date, comment status (enabled, disabled) and more.

The Admin Management Xtended WordPress plugin before 2.4.5 does not have CSRF checks in some of its AJAX actions, allowing attackers to make a logged users with the right capabilities to call them. This can lead to changes in post status (draft, published), slug, post date, comment status (enabled, disabled) and more.

EPSS

Процентиль: 45%
0.00229
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 6.5
nvd
больше 3 лет назад

The Admin Management Xtended WordPress plugin before 2.4.5 does not have CSRF checks in some of its AJAX actions, allowing attackers to make a logged users with the right capabilities to call them. This can lead to changes in post status (draft, published), slug, post date, comment status (enabled, disabled) and more.

EPSS

Процентиль: 45%
0.00229
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-352