Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vfrf-j3pc-4c2g

Опубликовано: 11 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The Make Email Customizer for WooCommerce WordPress plugin through 1.0.6 lacks proper authorization checks and option validation in its AJAX actions, allowing any authenticated user, such as a Subscriber, to update arbitrary WordPress options.

The Make Email Customizer for WooCommerce WordPress plugin through 1.0.6 lacks proper authorization checks and option validation in its AJAX actions, allowing any authenticated user, such as a Subscriber, to update arbitrary WordPress options.

EPSS

Процентиль: 2%
0.00014
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
3 месяца назад

The Make Email Customizer for WooCommerce WordPress plugin through 1.0.6 lacks proper authorization checks and option validation in its AJAX actions, allowing any authenticated user, such as a Subscriber, to update arbitrary WordPress options.

EPSS

Процентиль: 2%
0.00014
Низкий

5.3 Medium

CVSS3