Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f723-pfg4-v3p5

Опубликовано: 09 авг. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

The FULL - Customer plugin for WordPress is vulnerable to Arbitrary File Upload via the /install-plugin REST route in versions up to, and including, 2.2.3 due to improper authorization. This allows authenticated attackers with subscriber-level permissions and above to execute code by installing plugins from arbitrary remote locations including non-repository sources onto the site, granted they are packaged as a valid WordPress plugin.

The FULL - Customer plugin for WordPress is vulnerable to Arbitrary File Upload via the /install-plugin REST route in versions up to, and including, 2.2.3 due to improper authorization. This allows authenticated attackers with subscriber-level permissions and above to execute code by installing plugins from arbitrary remote locations including non-repository sources onto the site, granted they are packaged as a valid WordPress plugin.

EPSS

Процентиль: 67%
0.00531
Низкий

8.8 High

CVSS3

Дефекты

CWE-285
CWE-434

Связанные уязвимости

CVSS3: 8.8
nvd
больше 2 лет назад

The FULL - Customer plugin for WordPress is vulnerable to Arbitrary File Upload via the /install-plugin REST route in versions up to, and including, 2.2.3 due to improper authorization. This allows authenticated attackers with subscriber-level permissions and above to execute code by installing plugins from arbitrary remote locations including non-repository sources onto the site, granted they are packaged as a valid WordPress plugin.

EPSS

Процентиль: 67%
0.00531
Низкий

8.8 High

CVSS3

Дефекты

CWE-285
CWE-434