Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7j8c-j5qm-w6xf

Опубликовано: 07 июн. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

The Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_page_option function in versions up to, and including, 3.11.6. This makes it possible for authenticated attackers with subscriber-level capabilities to update arbitrary site options, which can lead to privilege escalation.

The Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_page_option function in versions up to, and including, 3.11.6. This makes it possible for authenticated attackers with subscriber-level capabilities to update arbitrary site options, which can lead to privilege escalation.

EPSS

Процентиль: 96%
0.26009
Средний

8.8 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 8.8
nvd
больше 2 лет назад

The Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_page_option function in versions up to, and including, 3.11.6. This makes it possible for authenticated attackers with subscriber-level capabilities to update arbitrary site options, which can lead to privilege escalation.

EPSS

Процентиль: 96%
0.26009
Средний

8.8 High

CVSS3

Дефекты

CWE-862