Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pcgf-phm5-g292

Опубликовано: 20 июл. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'woo_slg_login_email' function in all versions up to, and including, 2.7.3. This makes it possible for unauthenticated attackers to change the default role to Administrator while registering for an account.

The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'woo_slg_login_email' function in all versions up to, and including, 2.7.3. This makes it possible for unauthenticated attackers to change the default role to Administrator while registering for an account.

EPSS

Процентиль: 86%
0.02727
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 9.8
nvd
больше 1 года назад

The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'woo_slg_login_email' function in all versions up to, and including, 2.7.3. This makes it possible for unauthenticated attackers to change the default role to Administrator while registering for an account.

EPSS

Процентиль: 86%
0.02727
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-862