Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c7r4-v2h5-45gx

Опубликовано: 28 июн. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin WordPress plugin before 4.3.6 does not have authorisation and CSRF checks when resetting its settings, allowing unauthenticated attackers to reset them, including generating a new backup encryption key.

The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin WordPress plugin before 4.3.6 does not have authorisation and CSRF checks when resetting its settings, allowing unauthenticated attackers to reset them, including generating a new backup encryption key.

EPSS

Процентиль: 22%
0.00073
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-352
CWE-862

Связанные уязвимости

CVSS3: 4.3
nvd
больше 3 лет назад

The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin WordPress plugin before 4.3.6 does not have authorisation and CSRF checks when resetting its settings, allowing unauthenticated attackers to reset them, including generating a new backup encryption key.

EPSS

Процентиль: 22%
0.00073
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-352
CWE-862