Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w2v5-gfq2-4h2f

Опубликовано: 24 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.7

Описание

The Cornerstone WordPress plugin before 7.8.8 does not enforce capability checks on one of its CSS-preview request handlers, and exposes the nonce needed to call it to every logged-in user on any wp-admin page, allowing any authenticated user to evaluate dynamic content tokens against arbitrary users and disclose their sensitive metadata including raw password hashes. This affects the premium co Cornerstone page builder distributed bundled with the X , not the unrelated free cornerstone Cornerstone WordPress plugin before 7.8.8 (v0.8.x) on the .org repository.

The Cornerstone WordPress plugin before 7.8.8 does not enforce capability checks on one of its CSS-preview request handlers, and exposes the nonce needed to call it to every logged-in user on any wp-admin page, allowing any authenticated user to evaluate dynamic content tokens against arbitrary users and disclose their sensitive metadata including raw password hashes. This affects the premium co Cornerstone page builder distributed bundled with the X , not the unrelated free cornerstone Cornerstone WordPress plugin before 7.8.8 (v0.8.x) on the .org repository.

EPSS

Процентиль: 12%
0.00212
Низкий

7.7 High

CVSS3

Связанные уязвимости

CVSS3: 7.7
nvd
около 1 месяца назад

The Cornerstone WordPress plugin before 7.8.8 does not enforce capability checks on one of its CSS-preview request handlers, and exposes the nonce needed to call it to every logged-in user on any wp-admin page, allowing any authenticated user to evaluate dynamic content tokens against arbitrary users and disclose their sensitive metadata including raw password hashes. This affects the premium co Cornerstone page builder distributed bundled with the X , not the unrelated free `cornerstone` Cornerstone WordPress plugin before 7.8.8 (v0.8.x) on the .org repository.

EPSS

Процентиль: 12%
0.00212
Низкий

7.7 High

CVSS3