Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g2rw-4rqg-jqx5

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote authenticated users to create arbitrary users and gain admin privileges via a request to wpmp_pp_ajax_call with an execution target of wp_insert_user.

The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote authenticated users to create arbitrary users and gain admin privileges via a request to wpmp_pp_ajax_call with an execution target of wp_insert_user.

EPSS

Процентиль: 95%
0.18475
Средний

Связанные уязвимости

CVSS3: 8.8
nvd
больше 6 лет назад

The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote authenticated users to create arbitrary users and gain admin privileges via a request to wpmp_pp_ajax_call with an execution target of wp_insert_user.

EPSS

Процентиль: 95%
0.18475
Средний