Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-957h-97m4-9p53

Опубликовано: 14 дек. 2021
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

The Improved Include Page WordPress plugin through 1.2 allows passing shortcode attributes with post_type & post_status which can be used to retrieve arbitrary content. This way, users with a role as low as Contributor can gain access to content they are not supposed to.

The Improved Include Page WordPress plugin through 1.2 allows passing shortcode attributes with post_type & post_status which can be used to retrieve arbitrary content. This way, users with a role as low as Contributor can gain access to content they are not supposed to.

EPSS

Процентиль: 63%
0.0044
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 6.5
nvd
около 4 лет назад

The Improved Include Page WordPress plugin through 1.2 allows passing shortcode attributes with post_type & post_status which can be used to retrieve arbitrary content. This way, users with a role as low as Contributor can gain access to content they are not supposed to.

EPSS

Процентиль: 63%
0.0044
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-284