Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6xrg-c3gp-j55v

Опубликовано: 15 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

The Quick Featured Images plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 13.7.2 via the qfi_set_thumbnail and qfi_delete_thumbnail AJAX actions due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Author-level access and above, to change or remove featured images of other user's posts.

The Quick Featured Images plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 13.7.2 via the qfi_set_thumbnail and qfi_delete_thumbnail AJAX actions due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Author-level access and above, to change or remove featured images of other user's posts.

EPSS

Процентиль: 11%
0.00037
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 4.3
nvd
4 месяца назад

The Quick Featured Images plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 13.7.2 via the qfi_set_thumbnail and qfi_delete_thumbnail AJAX actions due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Author-level access and above, to change or remove featured images of other user's posts.

EPSS

Процентиль: 11%
0.00037
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-639