Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rp94-5jm7-95fv

Опубликовано: 29 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.6

Описание

The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorized plugin deactivation due to a missing capability check on the await_plugin_deactivation function in all versions up to, and including, 2.3.41. This makes it possible for authenticated attackers, with subscriber access or higher, to deactivate any active plugins.

The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorized plugin deactivation due to a missing capability check on the await_plugin_deactivation function in all versions up to, and including, 2.3.41. This makes it possible for authenticated attackers, with subscriber access or higher, to deactivate any active plugins.

EPSS

Процентиль: 20%
0.00064
Низкий

7.6 High

CVSS3

Связанные уязвимости

CVSS3: 7.6
nvd
почти 2 года назад

The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorized plugin deactivation due to a missing capability check on the await_plugin_deactivation function in all versions up to, and including, 2.3.41. This makes it possible for authenticated attackers, with subscriber access or higher, to deactivate any active plugins.

EPSS

Процентиль: 20%
0.00064
Низкий

7.6 High

CVSS3