Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h53x-g7f4-fggg

Опубликовано: 06 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.18.0 does not have proper authorisation checks in some of its REST endpoints, allowing unauthenticated users to call them and inject arbitrary CSS in arbitrary saved layouts

The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.18.0 does not have proper authorisation checks in some of its REST endpoints, allowing unauthenticated users to call them and inject arbitrary CSS in arbitrary saved layouts

EPSS

Процентиль: 66%
0.00519
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 6.1
nvd
больше 3 лет назад

The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.18.0 does not have proper authorisation checks in some of its REST endpoints, allowing unauthenticated users to call them and inject arbitrary CSS in arbitrary saved layouts

EPSS

Процентиль: 66%
0.00519
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-862