Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9mj4-xv45-qwq2

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The WP Statistics WordPress plugin before 13.0.8 relied on using the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query. Additionally, the page, which should have been accessible to administrator only, was also available to any visitor, including unauthenticated ones.

The WP Statistics WordPress plugin before 13.0.8 relied on using the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query. Additionally, the page, which should have been accessible to administrator only, was also available to any visitor, including unauthenticated ones.

EPSS

Процентиль: 99%
0.8326
Высокий

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 7.5
nvd
больше 4 лет назад

The WP Statistics WordPress plugin before 13.0.8 relied on using the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query. Additionally, the page, which should have been accessible to administrator only, was also available to any visitor, including unauthenticated ones.

EPSS

Процентиль: 99%
0.8326
Высокий

Дефекты

CWE-89