Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rggm-wjvh-78r5

Опубликовано: 08 фев. 2022
Источник: github
Github: Не прошло ревью

Описание

The Advanced Cron Manager WordPress plugin before 2.4.2, advanced-cron-manager-pro WordPress plugin before 2.5.3 does not have authorisation checks in some of its AJAX actions, allowing any authenticated users, such as subscriber to call them and add or remove events as well as schedules for example

The Advanced Cron Manager WordPress plugin before 2.4.2, advanced-cron-manager-pro WordPress plugin before 2.5.3 does not have authorisation checks in some of its AJAX actions, allowing any authenticated users, such as subscriber to call them and add or remove events as well as schedules for example

EPSS

Процентиль: 39%
0.0017
Низкий

Дефекты

CWE-284
CWE-862

Связанные уязвимости

CVSS3: 4.3
nvd
около 4 лет назад

The Advanced Cron Manager WordPress plugin before 2.4.2 and Advanced Cron Manager Pro WordPress plugin before 2.5.3 do not have authorisation checks in some of their AJAX actions, allowing any authenticated users, such as subscriber to call them and add or remove events as well as schedules for example

EPSS

Процентиль: 39%
0.0017
Низкий

Дефекты

CWE-284
CWE-862