Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vf8c-vc24-r3v4

Опубликовано: 14 июн. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter in an AJAX action, allowing unauthenticated users to call arbitrary PHP functions with no arguments.

The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter in an AJAX action, allowing unauthenticated users to call arbitrary PHP functions with no arguments.

EPSS

Процентиль: 99%
0.87241
Высокий

9.8 Critical

CVSS3

Дефекты

CWE-862
CWE-94

Связанные уязвимости

CVSS3: 9.8
nvd
больше 3 лет назад

The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter in an AJAX action, allowing unauthenticated users to call arbitrary PHP functions with no arguments.

EPSS

Процентиль: 99%
0.87241
Высокий

9.8 Critical

CVSS3

Дефекты

CWE-862
CWE-94