Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v5ff-x4w5-hjhp

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Insecure Deserialization in the Newsletter plugin before 6.8.2 for WordPress allows authenticated remote attackers with minimal privileges (such as subscribers) to use the tpnc_render AJAX action to inject arbitrary PHP objects via the options[inline_edits] parameter. NOTE: exploitability depends on PHP objects that might be present with certain other plugins or themes.

Insecure Deserialization in the Newsletter plugin before 6.8.2 for WordPress allows authenticated remote attackers with minimal privileges (such as subscribers) to use the tpnc_render AJAX action to inject arbitrary PHP objects via the options[inline_edits] parameter. NOTE: exploitability depends on PHP objects that might be present with certain other plugins or themes.

EPSS

Процентиль: 76%
0.0098
Низкий

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 7.5
nvd
около 5 лет назад

Insecure Deserialization in the Newsletter plugin before 6.8.2 for WordPress allows authenticated remote attackers with minimal privileges (such as subscribers) to use the tpnc_render AJAX action to inject arbitrary PHP objects via the options[inline_edits] parameter. NOTE: exploitability depends on PHP objects that might be present with certain other plugins or themes.

EPSS

Процентиль: 76%
0.0098
Низкий

Дефекты

CWE-502