Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f5c9-gcjw-ghvw

Опубликовано: 22 фев. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

The Coming soon and Maintenance mode WordPress plugin before 3.6.8 does not have authorisation and CSRF checks in its coming_soon_send_mail AJAX action, allowing any authenticated users, with a role as low as subscriber to send arbitrary emails to all subscribed users

The Coming soon and Maintenance mode WordPress plugin before 3.6.8 does not have authorisation and CSRF checks in its coming_soon_send_mail AJAX action, allowing any authenticated users, with a role as low as subscriber to send arbitrary emails to all subscribed users

EPSS

Процентиль: 25%
0.00087
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-352
CWE-863

Связанные уязвимости

CVSS3: 4.3
nvd
почти 4 года назад

The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not have authorisation and CSRF checks in its coming_soon_send_mail AJAX action, allowing any authenticated users, with a role as low as subscriber to send arbitrary emails to all subscribed users

EPSS

Процентиль: 25%
0.00087
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-352
CWE-863