Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q75g-rrjh-783v

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The sitepress-multilingual-cms (WPML) plugin before 4.3.7-b.2 for WordPress has CSRF due to a loose comparison. This leads to remote code execution in includes/class-wp-installer.php via a series of requests that leverage unintended comparisons of integers to strings.

The sitepress-multilingual-cms (WPML) plugin before 4.3.7-b.2 for WordPress has CSRF due to a loose comparison. This leads to remote code execution in includes/class-wp-installer.php via a series of requests that leverage unintended comparisons of integers to strings.

EPSS

Процентиль: 84%
0.02264
Низкий

Связанные уязвимости

CVSS3: 8.8
nvd
почти 6 лет назад

The sitepress-multilingual-cms (WPML) plugin before 4.3.7-b.2 for WordPress has CSRF due to a loose comparison. This leads to remote code execution in includes/class-wp-installer.php via a series of requests that leverage unintended comparisons of integers to strings.

EPSS

Процентиль: 84%
0.02264
Низкий