Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m4pp-cj4x-58f6

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a flaw in the social login implementation, allowing unauthenticated attacker to login as any user on the site by only knowing their user ID or username

The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a flaw in the social login implementation, allowing unauthenticated attacker to login as any user on the site by only knowing their user ID or username

EPSS

Процентиль: 99%
0.85031
Высокий

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 8.1
nvd
около 4 лет назад

The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a flaw in the social login implementation, allowing unauthenticated attacker to login as any user on the site by only knowing their user ID or username

EPSS

Процентиль: 99%
0.85031
Высокий

Дефекты

CWE-287