Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q943-6mg4-6px7

Опубликовано: 06 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

The Request a Quote Form plugin for WordPress is vulnerable to Remote Code Execution in version less than, or equal to, 2.5.2 via the emd_form_builder_lite_pagenum function. This is due to the plugin not properly validating user input before using it as a function name. This makes it possible for unauthenticated attackers to execute code on the server, however, parameters can not be passed to the functions called.

The Request a Quote Form plugin for WordPress is vulnerable to Remote Code Execution in version less than, or equal to, 2.5.2 via the emd_form_builder_lite_pagenum function. This is due to the plugin not properly validating user input before using it as a function name. This makes it possible for unauthenticated attackers to execute code on the server, however, parameters can not be passed to the functions called.

EPSS

Процентиль: 52%
0.00295
Низкий

8.1 High

CVSS3

Дефекты

CWE-95

Связанные уязвимости

CVSS3: 8.1
nvd
25 дней назад

The Request a Quote Form plugin for WordPress is vulnerable to Remote Code Execution in version less than, or equal to, 2.5.2 via the emd_form_builder_lite_pagenum function. This is due to the plugin not properly validating user input before using it as a function name. This makes it possible for unauthenticated attackers to execute code on the server, however, parameters can not be passed to the functions called.

EPSS

Процентиль: 52%
0.00295
Низкий

8.1 High

CVSS3

Дефекты

CWE-95