Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8w9m-69wv-wgjm

Опубликовано: 19 янв. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

The Social Warfare plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several AJAX actions in versions up to, and including, 4.3.0. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete post meta information and reset network access tokens.

The Social Warfare plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several AJAX actions in versions up to, and including, 4.3.0. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete post meta information and reset network access tokens.

EPSS

Процентиль: 9%
0.00032
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 5.4
nvd
около 3 лет назад

The Social Warfare plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several AJAX actions in versions up to, and including, 4.3.0. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete post meta information and reset network access tokens.

EPSS

Процентиль: 9%
0.00032
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-862