Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f32g-h75h-7vgp

Опубликовано: 25 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.6

Описание

The aoa-downloadable WordPress plugin through 0.1.0 doesn't validate a parameter in its download function, allowing unauthenticated attackers to download arbitrary files from the server

The aoa-downloadable WordPress plugin through 0.1.0 doesn't validate a parameter in its download function, allowing unauthenticated attackers to download arbitrary files from the server

EPSS

Процентиль: 45%
0.00224
Низкий

8.6 High

CVSS3

Связанные уязвимости

CVSS3: 8.6
nvd
11 месяцев назад

The aoa-downloadable WordPress plugin through 0.1.0 doesn't validate a parameter in its download function, allowing unauthenticated attackers to download arbitrary files from the server

EPSS

Процентиль: 45%
0.00224
Низкий

8.6 High

CVSS3