Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h5fr-p96x-74gc

Опубликовано: 02 авг. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

The CAPTCHA 4WP WordPress plugin before 7.1.0 lets user input reach a sensitive require_once call in one of its admin-side templates. This can be abused by attackers, via a Cross-Site Request Forgery attack to run arbitrary code on the server.

The CAPTCHA 4WP WordPress plugin before 7.1.0 lets user input reach a sensitive require_once call in one of its admin-side templates. This can be abused by attackers, via a Cross-Site Request Forgery attack to run arbitrary code on the server.

EPSS

Процентиль: 43%
0.00206
Низкий

8.8 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8.8
nvd
больше 3 лет назад

The CAPTCHA 4WP WordPress plugin before 7.1.0 lets user input reach a sensitive require_once call in one of its admin-side templates. This can be abused by attackers, via a Cross-Site Request Forgery attack to run arbitrary code on the server.

EPSS

Процентиль: 43%
0.00206
Низкий

8.8 High

CVSS3

Дефекты

CWE-352