Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qqm8-xpjj-m663

Опубликовано: 18 мар. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

The Enjoy Social Feed plugin for WordPress website WordPress plugin through 6.2.2 does not have authorisation and CSRF in various function hooked to admin_init, allowing unauthenticated users to call them and unlink arbitrary users Instagram Account for example

The Enjoy Social Feed plugin for WordPress website WordPress plugin through 6.2.2 does not have authorisation and CSRF in various function hooked to admin_init, allowing unauthenticated users to call them and unlink arbitrary users Instagram Account for example

EPSS

Процентиль: 54%
0.00308
Низкий

8.8 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8.8
nvd
почти 2 года назад

The Enjoy Social Feed plugin for WordPress website WordPress plugin through 6.2.2 does not have authorisation and CSRF in various function hooked to admin_init, allowing unauthenticated users to call them and unlink arbitrary users Instagram Account for example

EPSS

Процентиль: 54%
0.00308
Низкий

8.8 High

CVSS3

Дефекты

CWE-352