Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r7fx-x4q2-hqhr

Опубликовано: 07 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.6

Описание

The Host PHP Info plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when including the 'phpinfo' function in all versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to read configuration settings and predefined variables on the site's server. The plugin does not need to be activated for the vulnerability to be exploited.

The Host PHP Info plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when including the 'phpinfo' function in all versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to read configuration settings and predefined variables on the site's server. The plugin does not need to be activated for the vulnerability to be exploited.

EPSS

Процентиль: 94%
0.12453
Средний

8.6 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 8.6
nvd
около 1 года назад

The Host PHP Info plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when including the 'phpinfo' function in all versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to read configuration settings and predefined variables on the site's server. The plugin does not need to be activated for the vulnerability to be exploited.

EPSS

Процентиль: 94%
0.12453
Средний

8.6 High

CVSS3

Дефекты

CWE-862