Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cc2p-f3qf-3fr6

Опубликовано: 12 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

The Popup Builder WordPress plugin before 4.2.6 does not validate a parameter before making a request to it, which could allow users with the administrator role to perform SSRF attack in Multisite WordPress configurations.

The Popup Builder WordPress plugin before 4.2.6 does not validate a parameter before making a request to it, which could allow users with the administrator role to perform SSRF attack in Multisite WordPress configurations.

EPSS

Процентиль: 55%
0.00328
Низкий

7.5 High

CVSS3

Дефекты

CWE-22
CWE-352

Связанные уязвимости

CVSS3: 7.2
nvd
почти 2 года назад

The Popup Builder WordPress plugin before 4.2.6 does not validate a parameter before making a request to it, which could allow users with the administrator role to perform SSRF attack in Multisite WordPress configurations.

EPSS

Процентиль: 55%
0.00328
Низкий

7.5 High

CVSS3

Дефекты

CWE-22
CWE-352