Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g6pf-m72v-9jx7

Опубликовано: 25 нояб. 2021
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

WordPress Hide My WP plugin (versions <= 6.2.3) can be deactivated by any unauthenticated user. It is possible to retrieve a reset token which can then be used to deactivate the plugin.

WordPress Hide My WP plugin (versions <= 6.2.3) can be deactivated by any unauthenticated user. It is possible to retrieve a reset token which can then be used to deactivate the plugin.

EPSS

Процентиль: 79%
0.01236
Низкий

7.5 High

CVSS3

Дефекты

CWE-668
CWE-862

Связанные уязвимости

CVSS3: 6.5
nvd
около 4 лет назад

WordPress Hide My WP plugin (versions <= 6.2.3) can be deactivated by any unauthenticated user. It is possible to retrieve a reset token which can then be used to deactivate the plugin.

EPSS

Процентиль: 79%
0.01236
Низкий

7.5 High

CVSS3

Дефекты

CWE-668
CWE-862