Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-77j3-wqmc-3rp8

Опубликовано: 04 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create administrator accounts at will. This is actively being exploited in the wild.

The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create administrator accounts at will. This is actively being exploited in the wild.

EPSS

Процентиль: 100%
0.92971
Критический

9.8 Critical

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 9.8
nvd
больше 2 лет назад

The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create administrator accounts at will. This is actively being exploited in the wild.

EPSS

Процентиль: 100%
0.92971
Критический

9.8 Critical

CVSS3

Дефекты

CWE-269