Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hrmr-jgrx-82h5

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress allows yp_option_update CSRF, as demonstrated by use of yp_remote_get to obtain admin access.

The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress allows yp_option_update CSRF, as demonstrated by use of yp_remote_get to obtain admin access.

EPSS

Процентиль: 96%
0.28566
Средний

Связанные уязвимости

CVSS3: 8.8
nvd
больше 6 лет назад

The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress allows yp_option_update CSRF, as demonstrated by use of yp_remote_get to obtain admin access.

EPSS

Процентиль: 96%
0.28566
Средний