Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-657c-v2h8-hpvj

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The WPML plugin before 3.1.9 for WordPress does not properly handle multiple actions in a request, which allows remote attackers to bypass nonce checks and perform arbitrary actions via a request containing an action POST parameter, an action GET parameter, and a valid nonce for the action GET parameter.

The WPML plugin before 3.1.9 for WordPress does not properly handle multiple actions in a request, which allows remote attackers to bypass nonce checks and perform arbitrary actions via a request containing an action POST parameter, an action GET parameter, and a valid nonce for the action GET parameter.

EPSS

Процентиль: 62%
0.00431
Низкий

Дефекты

CWE-284

Связанные уязвимости

nvd
почти 11 лет назад

The WPML plugin before 3.1.9 for WordPress does not properly handle multiple actions in a request, which allows remote attackers to bypass nonce checks and perform arbitrary actions via a request containing an action POST parameter, an action GET parameter, and a valid nonce for the action GET parameter.

EPSS

Процентиль: 62%
0.00431
Низкий

Дефекты

CWE-284