Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j8g4-6p94-j4fp

Опубликовано: 19 июл. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The plugin Wbcom Designs – BuddyPress Group Reviews for WordPress is vulnerable to unauthorized settings changes and review modification due to missing capability checks and improper nonce checks in several functions related to said actions in versions up to, and including, 2.8.3. This makes it possible for unauthenticated attackers to modify reviews and plugin settings on the affected site.

The plugin Wbcom Designs – BuddyPress Group Reviews for WordPress is vulnerable to unauthorized settings changes and review modification due to missing capability checks and improper nonce checks in several functions related to said actions in versions up to, and including, 2.8.3. This makes it possible for unauthenticated attackers to modify reviews and plugin settings on the affected site.

EPSS

Процентиль: 71%
0.00693
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-862
CWE-863

Связанные уязвимости

CVSS3: 6.5
nvd
больше 3 лет назад

The plugin Wbcom Designs – BuddyPress Group Reviews for WordPress is vulnerable to unauthorized settings changes and review modification due to missing capability checks and improper nonce checks in several functions related to said actions in versions up to, and including, 2.8.3. This makes it possible for unauthenticated attackers to modify reviews and plugin settings on the affected site.

EPSS

Процентиль: 71%
0.00693
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-862
CWE-863