Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8mcm-2qrh-xcj8

Опубликовано: 09 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.6

Описание

The linkID plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when including the 'phpinfo' function in all versions up to, and including, 0.1.2. This makes it possible for unauthenticated attackers to read configuration settings and predefined variables on the site's server. The plugin does not need to be activated for the vulnerability to be exploited.

The linkID plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when including the 'phpinfo' function in all versions up to, and including, 0.1.2. This makes it possible for unauthenticated attackers to read configuration settings and predefined variables on the site's server. The plugin does not need to be activated for the vulnerability to be exploited.

EPSS

Процентиль: 97%
0.32492
Средний

8.6 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 8.6
nvd
около 1 года назад

The linkID plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when including the 'phpinfo' function in all versions up to, and including, 0.1.2. This makes it possible for unauthenticated attackers to read configuration settings and predefined variables on the site's server. The plugin does not need to be activated for the vulnerability to be exploited.

EPSS

Процентиль: 97%
0.32492
Средний

8.6 High

CVSS3

Дефекты

CWE-862