Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c7vr-vpm2-822g

Опубликовано: 19 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.8 via the invoicing viewer due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view invoices for completed orders which can contain PII of users.

The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.8 via the invoicing viewer due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view invoices for completed orders which can contain PII of users.

EPSS

Процентиль: 37%
0.00158
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-639
CWE-862

Связанные уязвимости

CVSS3: 5.3
nvd
12 месяцев назад

The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.8 via the invoicing viewer due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view invoices for completed orders which can contain PII of users.

EPSS

Процентиль: 37%
0.00158
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-639
CWE-862