Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p8qq-75v8-px25

Опубликовано: 28 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

The Cardealer theme for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.4 due to missing capability check on the 'save_settings' function. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify the default user role.

The Cardealer theme for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.4 due to missing capability check on the 'save_settings' function. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify the default user role.

EPSS

Процентиль: 45%
0.00222
Низкий

8.8 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 8.8
nvd
12 месяцев назад

The Cardealer theme for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.4 due to missing capability check on the 'save_settings' function. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify the default user role.

EPSS

Процентиль: 45%
0.00222
Низкий

8.8 High

CVSS3

Дефекты

CWE-862