Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q4vc-x2f4-45f6

Опубликовано: 21 фев. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

The Intuitive Custom Post Order WordPress plugin through 3.1.3 does not check for authorization in the update-menu-order ajax action, allowing any logged in user (with roles as low as Subscriber) to update the menu order

The Intuitive Custom Post Order WordPress plugin through 3.1.3 does not check for authorization in the update-menu-order ajax action, allowing any logged in user (with roles as low as Subscriber) to update the menu order

EPSS

Процентиль: 25%
0.00085
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 4.3
nvd
почти 3 года назад

The Intuitive Custom Post Order WordPress plugin before 3.1.4 does not check for authorization in the update-menu-order ajax action, allowing any logged in user (with roles as low as Subscriber) to update the menu order

EPSS

Процентиль: 25%
0.00085
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862