Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qp3j-j89p-hj4x

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A CSRF vulnerability in the RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote attackers to forge requests on behalf of a site administrator to change all settings for the plugin, including deleting users, creating new roles with escalated privileges, and allowing PHP file uploads via forms.

A CSRF vulnerability in the RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote attackers to forge requests on behalf of a site administrator to change all settings for the plugin, including deleting users, creating new roles with escalated privileges, and allowing PHP file uploads via forms.

EPSS

Процентиль: 68%
0.00569
Низкий

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8.8
nvd
почти 6 лет назад

A CSRF vulnerability in the RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote attackers to forge requests on behalf of a site administrator to change all settings for the plugin, including deleting users, creating new roles with escalated privileges, and allowing PHP file uploads via forms.

EPSS

Процентиль: 68%
0.00569
Низкий

Дефекты

CWE-352