Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rq4m-766g-9mx4

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote authenticated users (with minimal privileges) to import custom vulnerable forms and change form settings via class_rm_form_settings_controller.php, resulting in privilege escalation.

The RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote authenticated users (with minimal privileges) to import custom vulnerable forms and change form settings via class_rm_form_settings_controller.php, resulting in privilege escalation.

EPSS

Процентиль: 73%
0.00792
Низкий

Дефекты

CWE-269
CWE-862

Связанные уязвимости

CVSS3: 8.8
nvd
почти 6 лет назад

The RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote authenticated users (with minimal privileges) to import custom vulnerable forms and change form settings via class_rm_form_settings_controller.php, resulting in privilege escalation.

EPSS

Процентиль: 73%
0.00792
Низкий

Дефекты

CWE-269
CWE-862