Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-77v2-rrqg-jjqc

Опубликовано: 20 мая 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.8

Описание

The Decent Comments WordPress plugin before 3.0.2 does not restrict access to comment author email addresses and post author email addresses via its REST API endpoint, allowing unauthenticated attackers to enumerate registered user email addresses.

The Decent Comments WordPress plugin before 3.0.2 does not restrict access to comment author email addresses and post author email addresses via its REST API endpoint, allowing unauthenticated attackers to enumerate registered user email addresses.

EPSS

Процентиль: 19%
0.00271
Низкий

5.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.8
nvd
3 месяца назад

The Decent Comments WordPress plugin before 3.0.2 does not restrict access to comment author email addresses and post author email addresses via its REST API endpoint, allowing unauthenticated attackers to enumerate registered user email addresses.

EPSS

Процентиль: 19%
0.00271
Низкий

5.8 Medium

CVSS3