Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vrv9-62rj-7748

Опубликовано: 20 мар. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

The WooCommerce Multiple Customer Addresses & Shipping WordPress plugin before 21.7 does not ensure that the address to add/update/retrieve/delete and duplicate belong to the user making the request, or is from a high privilege users, allowing any authenticated users, such as subscriber to add/update/duplicate/delete as well as retrieve addresses of other users.

The WooCommerce Multiple Customer Addresses & Shipping WordPress plugin before 21.7 does not ensure that the address to add/update/retrieve/delete and duplicate belong to the user making the request, or is from a high privilege users, allowing any authenticated users, such as subscriber to add/update/duplicate/delete as well as retrieve addresses of other users.

EPSS

Процентиль: 89%
0.04322
Низкий

8.8 High

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 8.8
nvd
почти 3 года назад

The WooCommerce Multiple Customer Addresses & Shipping WordPress plugin before 21.7 does not ensure that the address to add/update/retrieve/delete and duplicate belong to the user making the request, or is from a high privilege users, allowing any authenticated users, such as subscriber to add/update/duplicate/delete as well as retrieve addresses of other users.

EPSS

Процентиль: 89%
0.04322
Низкий

8.8 High

CVSS3

Дефекты

CWE-639