Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w56v-4m7h-jhq8

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action.

wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action.

EPSS

Процентиль: 53%
0.00297
Низкий

Связанные уязвимости

ubuntu
больше 11 лет назад

wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action.

nvd
больше 11 лет назад

wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action.

debian
больше 11 лет назад

wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisi ...

EPSS

Процентиль: 53%
0.00297
Низкий