Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m4f6-5759-q864

Опубликовано: 05 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

The ShopLentor plugin for WordPress is vulnerable to arbitrary function execution via the woolentoropt/v1/custom-action REST API endpoint in all versions up to, and including, 3.3.7. This is due to the handle_action() method passing user-supplied input directly to call_user_func() without an allowlist of permitted callbacks. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute arbitrary PHP callable functions via the 'callback' parameter.

The ShopLentor plugin for WordPress is vulnerable to arbitrary function execution via the woolentoropt/v1/custom-action REST API endpoint in all versions up to, and including, 3.3.7. This is due to the handle_action() method passing user-supplied input directly to call_user_func() without an allowlist of permitted callbacks. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute arbitrary PHP callable functions via the 'callback' parameter.

EPSS

Процентиль: 43%
0.00539
Низкий

7.2 High

CVSS3

Дефекты

CWE-470

Связанные уязвимости

CVSS3: 7.2
nvd
14 дней назад

The ShopLentor plugin for WordPress is vulnerable to arbitrary function execution via the woolentoropt/v1/custom-action REST API endpoint in all versions up to, and including, 3.3.7. This is due to the handle_action() method passing user-supplied input directly to call_user_func() without an allowlist of permitted callbacks. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute arbitrary PHP callable functions via the 'callback' parameter.

EPSS

Процентиль: 43%
0.00539
Низкий

7.2 High

CVSS3

Дефекты

CWE-470