Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c7q7-2vr2-wj3p

Опубликовано: 22 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to unauthorized order creation in all versions up to, and including, 2.3.5. This is due to insufficient verification on form fields. This makes it possible for unauthenticated attackers to create new orders for products and mark them as paid without actually completing a payment.

The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to unauthorized order creation in all versions up to, and including, 2.3.5. This is due to insufficient verification on form fields. This makes it possible for unauthenticated attackers to create new orders for products and mark them as paid without actually completing a payment.

EPSS

Процентиль: 60%
0.00401
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 5.3
nvd
12 месяцев назад

The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to unauthorized order creation in all versions up to, and including, 2.3.5. This is due to insufficient verification on form fields. This makes it possible for unauthenticated attackers to create new orders for products and mark them as paid without actually completing a payment.

EPSS

Процентиль: 60%
0.00401
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-20