Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pfj9-w34v-grhw

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The VM Backups WordPress plugin through 1.0 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as update the plugin's options, leading to a Stored Cross-Site Scripting issue.

The VM Backups WordPress plugin through 1.0 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as update the plugin's options, leading to a Stored Cross-Site Scripting issue.

EPSS

Процентиль: 27%
0.00098
Низкий

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 6.1
nvd
почти 5 лет назад

The VM Backups WordPress plugin through 1.0 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as update the plugin's options, leading to a Stored Cross-Site Scripting issue.

EPSS

Процентиль: 27%
0.00098
Низкий

Дефекты

CWE-352