Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9wh9-687v-6mqp

Опубликовано: 28 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

The wpForo Forum plugin for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'update' method of the 'Members' class in all versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with subscriber-level privileges or higher, to read arbitrary files on the server.

The wpForo Forum plugin for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'update' method of the 'Members' class in all versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with subscriber-level privileges or higher, to read arbitrary files on the server.

EPSS

Процентиль: 36%
0.00154
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 6.5
nvd
11 месяцев назад

The wpForo Forum plugin for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'update' method of the 'Members' class in all versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with subscriber-level privileges or higher, to read arbitrary files on the server.

EPSS

Процентиль: 36%
0.00154
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-20