Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p4cv-qgmg-7q4w

Опубликовано: 12 июн. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The WordPress Single Sign-On (SSO) plugin for WordPress is vulnerable to unauthorized access due to a misconfigured capability check on a function in all versions up to, and including, the *.5.3 versions of the plugin. This makes it possible for unauthenticated attackers to extract sensitive data including site content that has been restricted to certain users and/or roles.

The WordPress Single Sign-On (SSO) plugin for WordPress is vulnerable to unauthorized access due to a misconfigured capability check on a function in all versions up to, and including, the *.5.3 versions of the plugin. This makes it possible for unauthenticated attackers to extract sensitive data including site content that has been restricted to certain users and/or roles.

EPSS

Процентиль: 25%
0.00083
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 5.3
nvd
6 месяцев назад

The WordPress Single Sign-On (SSO) plugin for WordPress is vulnerable to unauthorized access due to a misconfigured capability check on a function in all versions up to, and including, the *.5.3 versions of the plugin. This makes it possible for unauthenticated attackers to extract sensitive data including site content that has been restricted to certain users and/or roles.

EPSS

Процентиль: 25%
0.00083
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-863