Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jccv-rx29-7277

Опубликовано: 21 июн. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

The underConstruction WordPress plugin before 1.20 does not have CSRF check in place when deactivating the construction mode, which could allow attackers to make a logged in admin perform such action via a CSRF attack

The underConstruction WordPress plugin before 1.20 does not have CSRF check in place when deactivating the construction mode, which could allow attackers to make a logged in admin perform such action via a CSRF attack

EPSS

Процентиль: 30%
0.00112
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 4.3
nvd
больше 3 лет назад

The underConstruction WordPress plugin before 1.20 does not have CSRF check in place when deactivating the construction mode, which could allow attackers to make a logged in admin perform such action via a CSRF attack

EPSS

Процентиль: 30%
0.00112
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-352