Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fm3m-2gf9-6p64

Опубликовано: 26 июл. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper authorisation check in one of the AJAX action, available to unauthenticated (in v < 9.7.5) and author+ (in v9.7.5) users, allowing them to call it and retrieve various information such as the list of active plugins, various version like PHP, cURL, WP etc.

The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper authorisation check in one of the AJAX action, available to unauthenticated (in v < 9.7.5) and author+ (in v9.7.5) users, allowing them to call it and retrieve various information such as the list of active plugins, various version like PHP, cURL, WP etc.

EPSS

Процентиль: 97%
0.43978
Средний

5.3 Medium

CVSS3

Дефекты

CWE-200
CWE-863

Связанные уязвимости

CVSS3: 5.3
nvd
больше 3 лет назад

The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper authorisation check in one of the AJAX action, available to unauthenticated (in v < 9.7.5) and author+ (in v9.7.5) users, allowing them to call it and retrieve various information such as the list of active plugins, various version like PHP, cURL, WP etc.

EPSS

Процентиль: 97%
0.43978
Средний

5.3 Medium

CVSS3

Дефекты

CWE-200
CWE-863