Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q6fr-vjrc-hw6v

Опубликовано: 13 мар. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The Maintenance Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the subscribe_download function hooked via AJAX action in all versions up to, and including, 1.0.8. This makes it possible for authenticated attackers, with subscriber access or higher, to download a csv containing subscriber emails.

The Maintenance Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the subscribe_download function hooked via AJAX action in all versions up to, and including, 1.0.8. This makes it possible for authenticated attackers, with subscriber access or higher, to download a csv containing subscriber emails.

EPSS

Процентиль: 43%
0.00206
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
почти 2 года назад

The Maintenance Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the subscribe_download function hooked via AJAX action in all versions up to, and including, 1.0.8. This makes it possible for authenticated attackers, with subscriber access or higher, to download a csv containing subscriber emails.

EPSS

Процентиль: 43%
0.00206
Низкий

5.3 Medium

CVSS3