Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fvcq-6v6m-mmrf

Опубликовано: 13 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 4.2

Описание

The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.7.12 does not check ownership before changing the privacy level of an activity and its attached media, relying only on a nonce shared with every logged-in user, allowing users with a subscriber-level account or above to make another user's private activity public or hide it.

The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.7.12 does not check ownership before changing the privacy level of an activity and its attached media, relying only on a nonce shared with every logged-in user, allowing users with a subscriber-level account or above to make another user's private activity public or hide it.

EPSS

Процентиль: 2%
0.00119
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 4.2
nvd
10 дней назад

The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.7.12 does not check ownership before changing the privacy level of an activity and its attached media, relying only on a nonce shared with every logged-in user, allowing users with a subscriber-level account or above to make another user's private activity public or hide it.

EPSS

Процентиль: 2%
0.00119
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-639