Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gw4p-2m2w-qw96

Опубликовано: 09 июн. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

The Ask me WordPress theme before 6.8.2 does not perform CSRF checks for any of its AJAX actions, allowing an attacker to trick logged in users to perform various actions on their behalf on the site.

The Ask me WordPress theme before 6.8.2 does not perform CSRF checks for any of its AJAX actions, allowing an attacker to trick logged in users to perform various actions on their behalf on the site.

EPSS

Процентиль: 34%
0.0014
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 6.5
nvd
больше 3 лет назад

The Ask me WordPress theme before 6.8.2 does not perform CSRF checks for any of its AJAX actions, allowing an attacker to trick logged in users to perform various actions on their behalf on the site.

EPSS

Процентиль: 34%
0.0014
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-352