Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gmqc-8f92-w42j

Опубликовано: 27 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.7

Описание

The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor confine the stored file location to an allowed directory before serving it, allowing users with a role as low as subscriber to read arbitrary files on the server, including its configuration file and authentication secrets.

The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor confine the stored file location to an allowed directory before serving it, allowing users with a role as low as subscriber to read arbitrary files on the server, including its configuration file and authentication secrets.

EPSS

Процентиль: 17%
0.00249
Низкий

7.7 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.7
nvd
27 дней назад

The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor confine the stored file location to an allowed directory before serving it, allowing users with a role as low as subscriber to read arbitrary files on the server, including its configuration file and authentication secrets.

EPSS

Процентиль: 17%
0.00249
Низкий

7.7 High

CVSS3

Дефекты

CWE-200