Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mqx4-g9cq-jvc6

Опубликовано: 01 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 4.7

Описание

Themify WordPress plugin before 1.4.4 does not have CSRF check in its bulk action, which could allow attackers to make logged in users delete arbitrary filters via CSRF attack, granted they know the related filter slugs

Themify WordPress plugin before 1.4.4 does not have CSRF check in its bulk action, which could allow attackers to make logged in users delete arbitrary filters via CSRF attack, granted they know the related filter slugs

EPSS

Процентиль: 38%
0.00167
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 4.7
nvd
почти 2 года назад

Themify WordPress plugin before 1.4.4 does not have CSRF check in its bulk action, which could allow attackers to make logged in users delete arbitrary filters via CSRF attack, granted they know the related filter slugs

EPSS

Процентиль: 38%
0.00167
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-352