Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p288-w88f-r2qg

Опубликовано: 08 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow attackers with a subscriber account to conduct Stored XSS attacks.

The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow attackers with a subscriber account to conduct Stored XSS attacks.

EPSS

Процентиль: 49%
0.00255
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
около 2 лет назад

The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow attackers with a subscriber account to conduct Stored XSS attacks.

EPSS

Процентиль: 49%
0.00255
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79