Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9j2r-fq55-vh22

Опубликовано: 21 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.4

Описание

The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'uip_save_ui_template' function in all versions up to, and including, 3.5.08. This makes it possible for authenticated attackers, with Subscriber-level access and above, to save templates that contain custom JavaScript.

The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'uip_save_ui_template' function in all versions up to, and including, 3.5.08. This makes it possible for authenticated attackers, with Subscriber-level access and above, to save templates that contain custom JavaScript.

EPSS

Процентиль: 11%
0.00037
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 6.4
nvd
3 месяца назад

The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'uip_save_ui_template' function in all versions up to, and including, 3.5.08. This makes it possible for authenticated attackers, with Subscriber-level access and above, to save templates that contain custom JavaScript.

EPSS

Процентиль: 11%
0.00037
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-862