Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jjrq-h892-h3gx

Опубликовано: 11 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.3

Описание

The Hostinger plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the function publish_website in all versions up to, and including, 1.9.7. This makes it possible for unauthenticated attackers to enable and disable maintenance mode.

The Hostinger plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the function publish_website in all versions up to, and including, 1.9.7. This makes it possible for unauthenticated attackers to enable and disable maintenance mode.

EPSS

Процентиль: 36%
0.00154
Низкий

7.3 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 7.3
nvd
около 2 лет назад

The Hostinger plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the function publish_website in all versions up to, and including, 1.9.7. This makes it possible for unauthenticated attackers to enable and disable maintenance mode.

CVSS3: 7.3
fstec
около 3 лет назад

Уязвимость функции public_website() плагина Hostinger системы управления содержимым сайта WordPress, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 36%
0.00154
Низкий

7.3 High

CVSS3

Дефекты

CWE-862