Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f2j9-593v-67w7

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Include Me WordPress plugin through 1.2.1 is vulnerable to path traversal / local file inclusion, which can lead to Remote Code Execution (RCE) of the system due to log poisoning and therefore potentially a full compromise of the underlying structure

The Include Me WordPress plugin through 1.2.1 is vulnerable to path traversal / local file inclusion, which can lead to Remote Code Execution (RCE) of the system due to log poisoning and therefore potentially a full compromise of the underlying structure

EPSS

Процентиль: 91%
0.07222
Низкий

Дефекты

CWE-22
CWE-94

Связанные уязвимости

CVSS3: 8.8
nvd
больше 4 лет назад

The Include Me WordPress plugin through 1.2.1 is vulnerable to path traversal / local file inclusion, which can lead to Remote Code Execution (RCE) of the system due to log poisoning and therefore potentially a full compromise of the underlying structure

EPSS

Процентиль: 91%
0.07222
Низкий

Дефекты

CWE-22
CWE-94