Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j6r3-vq2c-4ghw

Опубликовано: 16 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The Defender Security WordPress plugin before 4.1.0 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the login page, even when the hide login page functionality of the plugin is enabled.

The Defender Security WordPress plugin before 4.1.0 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the login page, even when the hide login page functionality of the plugin is enabled.

EPSS

Процентиль: 99%
0.8275
Высокий

5.3 Medium

CVSS3

Дефекты

CWE-209

Связанные уязвимости

CVSS3: 5.3
nvd
больше 2 лет назад

The Defender Security WordPress plugin before 4.1.0 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the login page, even when the hide login page functionality of the plugin is enabled.

EPSS

Процентиль: 99%
0.8275
Высокий

5.3 Medium

CVSS3

Дефекты

CWE-209