Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qrvc-x2cw-mgcp

Опубликовано: 14 дек. 2021
Источник: github
Github: Не прошло ревью

Описание

The Page/Post Content Shortcode WordPress plugin through 1.0 does not have proper authorisation in place, allowing users with a role as low as contributor to access draft/private/password protected/trashed posts/pages they should not be allowed to, including posts created by other users such as admins and editors.

The Page/Post Content Shortcode WordPress plugin through 1.0 does not have proper authorisation in place, allowing users with a role as low as contributor to access draft/private/password protected/trashed posts/pages they should not be allowed to, including posts created by other users such as admins and editors.

EPSS

Процентиль: 40%
0.00186
Низкий

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 4.3
nvd
около 4 лет назад

The Page/Post Content Shortcode WordPress plugin through 1.0 does not have proper authorisation in place, allowing users with a role as low as contributor to access draft/private/password protected/trashed posts/pages they should not be allowed to, including posts created by other users such as admins and editors.

EPSS

Процентиль: 40%
0.00186
Низкий

Дефекты

CWE-863