Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6h5p-8mvr-f4fg

Опубликовано: 22 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'email' action in all versions up to, and including, 5.8.1. This makes it possible for authenticated attackers, with contributor-level access and above, to email the attendees list to themselves.

The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'email' action in all versions up to, and including, 5.8.1. This makes it possible for authenticated attackers, with contributor-level access and above, to email the attendees list to themselves.

EPSS

Процентиль: 35%
0.00141
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 4.3
nvd
почти 2 года назад

The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'email' action in all versions up to, and including, 5.8.1. This makes it possible for authenticated attackers, with contributor-level access and above, to email the attendees list to themselves.

EPSS

Процентиль: 35%
0.00141
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862