Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9688-4r62-68pj

Опубликовано: 02 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.9

Описание

The Upload.am WordPress plugin before 1.0.1 is vulnerable to arbitrary option disclosure due to a missing capability check on its AJAX request handler, allowing users such as contributor to view site options.

The Upload.am WordPress plugin before 1.0.1 is vulnerable to arbitrary option disclosure due to a missing capability check on its AJAX request handler, allowing users such as contributor to view site options.

EPSS

Процентиль: 11%
0.00037
Низкий

4.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.9
nvd
2 месяца назад

The Upload.am WordPress plugin before 1.0.1 is vulnerable to arbitrary option disclosure due to a missing capability check on its AJAX request handler, allowing users such as contributor to view site options.

EPSS

Процентиль: 11%
0.00037
Низкий

4.9 Medium

CVSS3