Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f68r-j6f2-hvjm

Опубликовано: 31 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

The HT Event – WordPress Event Manager Plugin for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.7 via the 'render' function in /includes/widgets/htevent_sponsor.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, scheduled, and draft template data.

The HT Event – WordPress Event Manager Plugin for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.7 via the 'render' function in /includes/widgets/htevent_sponsor.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, scheduled, and draft template data.

EPSS

Процентиль: 32%
0.00122
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-359

Связанные уязвимости

CVSS3: 4.3
nvd
около 1 года назад

The HT Event – WordPress Event Manager Plugin for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.7 via the 'render' function in /includes/widgets/htevent_sponsor.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, scheduled, and draft template data.

EPSS

Процентиль: 32%
0.00122
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-359