Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-73jw-m44p-r46h

Опубликовано: 11 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel WordPress plugin before 2.2.76 does not prevent password protected posts from being displayed in the result of some unauthenticated AJAX actions, allowing unauthenticated users to read such posts

The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel WordPress plugin before 2.2.76 does not prevent password protected posts from being displayed in the result of some unauthenticated AJAX actions, allowing unauthenticated users to read such posts

EPSS

Процентиль: 94%
0.13073
Средний

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
почти 2 года назад

The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel WordPress plugin before 2.2.76 does not have proper authorization, resulting in password protected posts to be displayed in the result of some unauthenticated AJAX actions, allowing unauthenticated users to read such posts

EPSS

Процентиль: 94%
0.13073
Средний

5.4 Medium

CVSS3