Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9mf8-fwp6-wv6x

Опубликовано: 21 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The Mstoreapp Mobile App WordPress plugin through 2.08 and Mstoreapp Mobile Multivendor through 9.0.1 do not properly verify users identify when using an AJAX action, allowing unauthenticated users to retrieve a valid session for arbitrary users by knowing their email address.

The Mstoreapp Mobile App WordPress plugin through 2.08 and Mstoreapp Mobile Multivendor through 9.0.1 do not properly verify users identify when using an AJAX action, allowing unauthenticated users to retrieve a valid session for arbitrary users by knowing their email address.

EPSS

Процентиль: 35%
0.00147
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
3 месяца назад

The Mstoreapp Mobile App WordPress plugin through 2.08 and Mstoreapp Mobile Multivendor through 9.0.1 do not properly verify users identify when using an AJAX action, allowing unauthenticated users to retrieve a valid session for arbitrary users by knowing their email address.

EPSS

Процентиль: 35%
0.00147
Низкий

9.8 Critical

CVSS3