Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hw84-c76j-h87p

Опубликовано: 14 мая 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the several functions in versions up to, and including, 6.20.01. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to edit plugin settings, including storing cross-site scripting, in multisite environments.

The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the several functions in versions up to, and including, 6.20.01. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to edit plugin settings, including storing cross-site scripting, in multisite environments.

EPSS

Процентиль: 40%
0.00182
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 6.5
nvd
больше 1 года назад

The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the several functions in versions up to, and including, 6.20.01. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to edit plugin settings, including storing cross-site scripting, in multisite environments.

EPSS

Процентиль: 40%
0.00182
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-601