Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c58r-vwf8-vx95

Опубликовано: 23 янв. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

The Passster WordPress plugin before 3.5.5.9 does not properly check for password, as well as that the post to be viewed is public, allowing unauthenticated users to bypass the protection offered by the plugin, and access arbitrary posts (such as private) content, by sending a specifically crafted request.

The Passster WordPress plugin before 3.5.5.9 does not properly check for password, as well as that the post to be viewed is public, allowing unauthenticated users to bypass the protection offered by the plugin, and access arbitrary posts (such as private) content, by sending a specifically crafted request.

EPSS

Процентиль: 78%
0.01101
Низкий

7.5 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 7.5
nvd
около 3 лет назад

The Passster WordPress plugin before 3.5.5.9 does not properly check for password, as well as that the post to be viewed is public, allowing unauthenticated users to bypass the protection offered by the plugin, and access arbitrary posts (such as private) content, by sending a specifically crafted request.

EPSS

Процентиль: 78%
0.01101
Низкий

7.5 High

CVSS3

Дефекты

CWE-287