Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jchc-3px4-v985

Опубликовано: 10 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

The FoodBoxBooker WordPress plugin before 1.0.8 does not verify that the user account being updated belongs to the user making the request, allowing authenticated users, with Subscriber-level access and above, to modify the profile details of arbitrary users, including administrators.

The FoodBoxBooker WordPress plugin before 1.0.8 does not verify that the user account being updated belongs to the user making the request, allowing authenticated users, with Subscriber-level access and above, to modify the profile details of arbitrary users, including administrators.

EPSS

Процентиль: 5%
0.00152
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 4.3
nvd
около 1 месяца назад

The FoodBoxBooker WordPress plugin before 1.0.8 does not verify that the user account being updated belongs to the user making the request, allowing authenticated users, with Subscriber-level access and above, to modify the profile details of arbitrary users, including administrators.

EPSS

Процентиль: 5%
0.00152
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-639