Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w32c-7vqv-h5gw

Опубликовано: 16 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve email addresses of any users on the blog

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve email addresses of any users on the blog

EPSS

Процентиль: 99%
0.87324
Высокий

5.3 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 5.3
nvd
около 2 лет назад

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve email addresses of any users on the blog

EPSS

Процентиль: 99%
0.87324
Высокий

5.3 Medium

CVSS3

Дефекты

CWE-862