Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w5vw-x33c-r8g6

Опубликовано: 13 мар. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

The Popup Builder by OptinMonster WordPress plugin before 2.12.2 does not ensure that the campaign to be loaded via some shortcodes is actually a campaign, allowing any authenticated users such as subscriber to retrieve the content of arbitrary posts, like draft, private or even password protected ones.

The Popup Builder by OptinMonster WordPress plugin before 2.12.2 does not ensure that the campaign to be loaded via some shortcodes is actually a campaign, allowing any authenticated users such as subscriber to retrieve the content of arbitrary posts, like draft, private or even password protected ones.

EPSS

Процентиль: 63%
0.0044
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 6.5
nvd
почти 3 года назад

The Popup Builder by OptinMonster WordPress plugin before 2.12.2 does not ensure that the campaign to be loaded via some shortcodes is actually a campaign, allowing any authenticated users such as subscriber to retrieve the content of arbitrary posts, like draft, private or even password protected ones.

EPSS

Процентиль: 63%
0.0044
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-639