Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fr3h-4rcw-wvmj

Опубликовано: 07 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to read arbitrary feedbacks data sent via the Jetpack Contact Form

The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to read arbitrary feedbacks data sent via the Jetpack Contact Form

EPSS

Процентиль: 95%
0.18125
Средний

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
больше 1 года назад

The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to read arbitrary feedbacks data sent via the Jetpack Contact Form

EPSS

Процентиль: 95%
0.18125
Средний

4.3 Medium

CVSS3