Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rw6j-4w4v-pm7m

Опубликовано: 12 апр. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain admin access on a site that has the affected version of the plugin activated.

An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain admin access on a site that has the affected version of the plugin activated.

EPSS

Процентиль: 100%
0.93348
Критический

9.8 Critical

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.8
nvd
почти 3 года назад

An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain admin access on a site that has the affected version of the plugin activated.

EPSS

Процентиль: 100%
0.93348
Критический

9.8 Critical

CVSS3

Дефекты

CWE-287