Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-87w4-xwrv-8vj5

Опубликовано: 20 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboarding/module.php file that make it possible for attackers to modify site data in addition to uploading malicious files that can be used to obtain remote code execution, in versions 3.6.0 to 3.6.2.

The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboarding/module.php file that make it possible for attackers to modify site data in addition to uploading malicious files that can be used to obtain remote code execution, in versions 3.6.0 to 3.6.2.

EPSS

Процентиль: 100%
0.93475
Критический

8.8 High

CVSS3

Дефекты

CWE-434
CWE-862

Связанные уязвимости

CVSS3: 8.8
nvd
почти 4 года назад

The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboarding/module.php file that make it possible for attackers to modify site data in addition to uploading malicious files that can be used to obtain remote code execution, in versions 3.6.0 to 3.6.2.

EPSS

Процентиль: 100%
0.93475
Критический

8.8 High

CVSS3

Дефекты

CWE-434
CWE-862