Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pm3v-7943-w34p

Опубликовано: 15 фев. 2022
Источник: github
Github: Не прошло ревью

Описание

The Ibtana WordPress plugin before 1.1.4.9 does not have authorisation and CSRF checks in the ive_save_general_settings AJAX action, allowing any authenticated users, such as subscriber to call it and change the plugin's settings which could lead to Stored Cross-Site Scripting issue.

The Ibtana WordPress plugin before 1.1.4.9 does not have authorisation and CSRF checks in the ive_save_general_settings AJAX action, allowing any authenticated users, such as subscriber to call it and change the plugin's settings which could lead to Stored Cross-Site Scripting issue.

EPSS

Процентиль: 40%
0.0018
Низкий

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 3.5
nvd
почти 4 года назад

The Ibtana WordPress plugin before 1.1.4.9 does not have authorisation and CSRF checks in the ive_save_general_settings AJAX action, allowing any authenticated users, such as subscriber to call it and change the plugin's settings which could lead to Stored Cross-Site Scripting issue.

EPSS

Процентиль: 40%
0.0018
Низкий

Дефекты

CWE-862