Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r9p3-w49v-jhxq

Опубликовано: 26 дек. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

The Workreap WordPress theme before 2.6.4 does not verify that an addon service belongs to the user issuing the request, or indeed that it is an addon service, when processing the workreap_addons_service_remove action, allowing any user to delete any post by knowing or guessing the id.

The Workreap WordPress theme before 2.6.4 does not verify that an addon service belongs to the user issuing the request, or indeed that it is an addon service, when processing the workreap_addons_service_remove action, allowing any user to delete any post by knowing or guessing the id.

EPSS

Процентиль: 41%
0.0019
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 6.5
nvd
около 3 лет назад

The Workreap WordPress theme before 2.6.4 does not verify that an addon service belongs to the user issuing the request, or indeed that it is an addon service, when processing the workreap_addons_service_remove action, allowing any user to delete any post by knowing or guessing the id.

EPSS

Процентиль: 41%
0.0019
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-639