Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7f48-x47w-f5p2

Опубликовано: 05 апр. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

The WCFM Membership plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 2.10.0 due to missing capability checks on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of actions such as modifying membership details, changing renewal information, controlling membership approvals, and more.

The WCFM Membership plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 2.10.0 due to missing capability checks on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of actions such as modifying membership details, changing renewal information, controlling membership approvals, and more.

EPSS

Процентиль: 94%
0.15335
Средний

6.5 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 7.3
nvd
почти 3 года назад

The WCFM Membership plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 2.10.0 due to missing capability checks on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of actions such as modifying membership details, changing renewal information, controlling membership approvals, and more.

EPSS

Процентиль: 94%
0.15335
Средний

6.5 Medium

CVSS3

Дефекты

CWE-862