Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w72q-xj4x-r776

Опубликовано: 13 мар. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

The Ocean Extra WordPress plugin before 2.1.3 does not ensure that the template to be loaded via a shortcode is actually a template, allowing any authenticated users such as subscriber to retrieve the content of arbitrary posts, such as draft, private or even password protected ones.

The Ocean Extra WordPress plugin before 2.1.3 does not ensure that the template to be loaded via a shortcode is actually a template, allowing any authenticated users such as subscriber to retrieve the content of arbitrary posts, such as draft, private or even password protected ones.

EPSS

Процентиль: 53%
0.00296
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 6.5
nvd
почти 3 года назад

The Ocean Extra WordPress plugin before 2.1.3 does not ensure that the template to be loaded via a shortcode is actually a template, allowing any authenticated users such as subscriber to retrieve the content of arbitrary posts, such as draft, private or even password protected ones.

EPSS

Процентиль: 53%
0.00296
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-639