Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r487-g863-pm8x

Опубликовано: 03 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

The Sitemap by click5 WordPress plugin before 1.0.36 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the plugin. As a result, unauthenticated attackers could change arbitrary blog options, such as the users_can_register and default_role, allowing them to create a new admin account and take over the blog.

The Sitemap by click5 WordPress plugin before 1.0.36 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the plugin. As a result, unauthenticated attackers could change arbitrary blog options, such as the users_can_register and default_role, allowing them to create a new admin account and take over the blog.

EPSS

Процентиль: 100%
0.89187
Высокий

8.8 High

CVSS3

Дефекты

CWE-352
CWE-862

Связанные уязвимости

CVSS3: 8.8
nvd
почти 4 года назад

The Sitemap by click5 WordPress plugin before 1.0.36 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the plugin. As a result, unauthenticated attackers could change arbitrary blog options, such as the users_can_register and default_role, allowing them to create a new admin account and take over the blog.

CVSS3: 8.8
fstec
больше 2 лет назад

Уязвимость плагина Sitemap by click5 системы управления содержимым сайта WordPress, позволяющая нарушителю создать учетную запись с правами администратора и осуществить CSRF-атаку

EPSS

Процентиль: 100%
0.89187
Высокий

8.8 High

CVSS3

Дефекты

CWE-352
CWE-862