Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7579-vg8j-qmq7

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The WP Attachment Export WordPress plugin before 0.2.4 does not have proper access controls, allowing unauthenticated users to download the XML data that holds all the details of attachments/posts on a Wordpress

The WP Attachment Export WordPress plugin before 0.2.4 does not have proper access controls, allowing unauthenticated users to download the XML data that holds all the details of attachments/posts on a Wordpress

EPSS

Процентиль: 95%
0.19119
Средний

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 7.5
nvd
больше 4 лет назад

The WP Attachment Export WordPress plugin before 0.2.4 does not have proper access controls, allowing unauthenticated users to download the XML data that holds all the details of attachments/posts on a Wordpress

EPSS

Процентиль: 95%
0.19119
Средний

Дефекты

CWE-862