Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-95jv-pcxp-g9qj

Опубликовано: 08 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

The WP VR WordPress plugin before 8.3.15 does not authorisation and CSRF in a function hooked to admin_init, allowing unauthenticated users to downgrade the plugin, thus leading to Reflected or Stored XSS, as previous versions have such vulnerabilities.

The WP VR WordPress plugin before 8.3.15 does not authorisation and CSRF in a function hooked to admin_init, allowing unauthenticated users to downgrade the plugin, thus leading to Reflected or Stored XSS, as previous versions have such vulnerabilities.

EPSS

Процентиль: 67%
0.00532
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-352
CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
около 2 лет назад

The WP VR WordPress plugin before 8.3.15 does not authorisation and CSRF in a function hooked to admin_init, allowing unauthenticated users to downgrade the plugin, thus leading to Reflected or Stored XSS, as previous versions have such vulnerabilities.

EPSS

Процентиль: 67%
0.00532
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-352
CWE-79