Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f76v-rqvc-f4rw

Опубликовано: 30 нояб. 2021
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

The Bulk Datetime Change WordPress plugin before 1.12 does not enforce capability checks which allows users with Contributor roles to 1) list private post titles of other users and 2) change the posted date of other users' posts.

The Bulk Datetime Change WordPress plugin before 1.12 does not enforce capability checks which allows users with Contributor roles to 1) list private post titles of other users and 2) change the posted date of other users' posts.

EPSS

Процентиль: 35%
0.00146
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-862
CWE-863

Связанные уязвимости

CVSS3: 5.4
nvd
около 4 лет назад

The Bulk Datetime Change WordPress plugin before 1.12 does not enforce capability checks which allows users with Contributor roles to 1) list private post titles of other users and 2) change the posted date of other users' posts.

EPSS

Процентиль: 35%
0.00146
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-862
CWE-863