Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cvg2-rcw5-j6vm

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Delete All Comments Easily WordPress plugin through 1.3 is lacking Cross-Site Request Forgery (CSRF) checks, which could result in an unauthenticated attacker making a logged in admin delete all comments from the blog.

The Delete All Comments Easily WordPress plugin through 1.3 is lacking Cross-Site Request Forgery (CSRF) checks, which could result in an unauthenticated attacker making a logged in admin delete all comments from the blog.

EPSS

Процентиль: 44%
0.00214
Низкий

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 6.5
nvd
больше 4 лет назад

The Delete All Comments Easily WordPress plugin through 1.3 is lacking Cross-Site Request Forgery (CSRF) checks, which could result in an unauthenticated attacker making a logged in admin delete all comments from the blog.

EPSS

Процентиль: 44%
0.00214
Низкий

Дефекты

CWE-352