Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9j68-9p63-wh2j

Опубликовано: 18 нояб. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

Broken Access Control vulnerability in WPML Multilingual CMS premium plugin <= 4.5.10 on WordPress allows users with a subscriber or higher user role to change plugin settings (selected language for legacy widgets, the default behavior for media content).

Broken Access Control vulnerability in WPML Multilingual CMS premium plugin <= 4.5.10 on WordPress allows users with a subscriber or higher user role to change plugin settings (selected language for legacy widgets, the default behavior for media content).

EPSS

Процентиль: 40%
0.00182
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 5.4
nvd
около 3 лет назад

Broken Access Control vulnerability in WPML Multilingual CMS premium plugin <= 4.5.10 on WordPress allows users with a subscriber or higher user role to change plugin settings (selected language for legacy widgets, the default behavior for media content).

EPSS

Процентиль: 40%
0.00182
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-732