Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gwvq-pm88-g84j

Опубликовано: 18 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

The SiteOrigin Widgets Bundle WordPress plugin before 1.51.0 does not validate user input before using it to generate paths passed to include function/s, allowing users with the administrator role to perform LFI attacks in the context of Multisite WordPress sites.

The SiteOrigin Widgets Bundle WordPress plugin before 1.51.0 does not validate user input before using it to generate paths passed to include function/s, allowing users with the administrator role to perform LFI attacks in the context of Multisite WordPress sites.

EPSS

Процентиль: 57%
0.00347
Низкий

7.2 High

CVSS3

Связанные уязвимости

CVSS3: 7.2
nvd
около 2 лет назад

The SiteOrigin Widgets Bundle WordPress plugin before 1.51.0 does not validate user input before using it to generate paths passed to include function/s, allowing users with the administrator role to perform LFI attacks in the context of Multisite WordPress sites.

EPSS

Процентиль: 57%
0.00347
Низкий

7.2 High

CVSS3