Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v7hx-7773-729x

Опубликовано: 14 дек. 2021
Источник: github
Github: Не прошло ревью
CVSS3: 8

Описание

The Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.38 does not have any authorisation and CSRF checks in the likebtn_export_votes AJAX action, which could allow any authenticated user, such as subscriber, to get a list of email and IP addresses of people who liked content from the blog.

The Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.38 does not have any authorisation and CSRF checks in the likebtn_export_votes AJAX action, which could allow any authenticated user, such as subscriber, to get a list of email and IP addresses of people who liked content from the blog.

EPSS

Процентиль: 34%
0.00141
Низкий

8 High

CVSS3

Дефекты

CWE-200
CWE-352

Связанные уязвимости

CVSS3: 8
nvd
около 4 лет назад

The Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.38 does not have any authorisation and CSRF checks in the likebtn_export_votes AJAX action, which could allow any authenticated user, such as subscriber, to get a list of email and IP addresses of people who liked content from the blog.

EPSS

Процентиль: 34%
0.00141
Низкий

8 High

CVSS3

Дефекты

CWE-200
CWE-352