Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w87w-64p4-f94p

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The AutomatorWP WordPress plugin before 1.7.6 does not perform capability checks which allows users with Subscriber roles to enumerate automations, disclose title of private posts or user emails, call functions, or perform privilege escalation via Ajax actions.

The AutomatorWP WordPress plugin before 1.7.6 does not perform capability checks which allows users with Subscriber roles to enumerate automations, disclose title of private posts or user emails, call functions, or perform privilege escalation via Ajax actions.

EPSS

Процентиль: 47%
0.00241
Низкий

Дефекты

CWE-269
CWE-863

Связанные уязвимости

CVSS3: 8.8
nvd
больше 4 лет назад

The AutomatorWP WordPress plugin before 1.7.6 does not perform capability checks which allows users with Subscriber roles to enumerate automations, disclose title of private posts or user emails, call functions, or perform privilege escalation via Ajax actions.

EPSS

Процентиль: 47%
0.00241
Низкий

Дефекты

CWE-269
CWE-863