Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f6x2-w8q2-ff47

Опубликовано: 17 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

The PuppyFW WordPress plugin through 0.4.4 does not have proper authorisation on one of its REST routes, which tests the caller against a capability taken from the request itself, allowing any authenticated user, including subscribers, to add, modify and delete arbitrary blog options and thereby escalate their privileges.

The PuppyFW WordPress plugin through 0.4.4 does not have proper authorisation on one of its REST routes, which tests the caller against a capability taken from the request itself, allowing any authenticated user, including subscribers, to add, modify and delete arbitrary blog options and thereby escalate their privileges.

EPSS

Процентиль: 14%
0.00232
Низкий

8.8 High

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 8.8
nvd
6 дней назад

The PuppyFW WordPress plugin through 0.4.4 does not have proper authorisation on one of its REST routes, which tests the caller against a capability taken from the request itself, allowing any authenticated user, including subscribers, to add, modify and delete arbitrary blog options and thereby escalate their privileges.

EPSS

Процентиль: 14%
0.00232
Низкий

8.8 High

CVSS3

Дефекты

CWE-269