Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rfc7-p29x-qh35

Опубликовано: 03 апр. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

The User Role by BestWebSoft WordPress plugin before 1.6.7 does not protect against CSRF in requests to update role capabilities, leading to arbitrary privilege escalation of any role.

The User Role by BestWebSoft WordPress plugin before 1.6.7 does not protect against CSRF in requests to update role capabilities, leading to arbitrary privilege escalation of any role.

EPSS

Процентиль: 34%
0.00141
Низкий

8.8 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8.8
nvd
почти 3 года назад

The User Role by BestWebSoft WordPress plugin before 1.6.7 does not protect against CSRF in requests to update role capabilities, leading to arbitrary privilege escalation of any role.

EPSS

Процентиль: 34%
0.00141
Низкий

8.8 High

CVSS3

Дефекты

CWE-352