Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w3jq-wqph-2fhr

Опубликовано: 25 сент. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.1.0.1. This is due to the plugin not properly restricting what users a group leader can edit. This makes it possible for authenticated attackers, with group leader-level access and above, to change admin account email addresses which can subsequently lead to admin account access.

The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.1.0.1. This is due to the plugin not properly restricting what users a group leader can edit. This makes it possible for authenticated attackers, with group leader-level access and above, to change admin account email addresses which can subsequently lead to admin account access.

EPSS

Процентиль: 86%
0.03072
Низкий

7.2 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 7.2
nvd
больше 1 года назад

The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.1.0.1. This is due to the plugin not properly restricting what users a group leader can edit. This makes it possible for authenticated attackers, with group leader-level access and above, to change admin account email addresses which can subsequently lead to admin account access.

EPSS

Процентиль: 86%
0.03072
Низкий

7.2 High

CVSS3

Дефекты

CWE-862