Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wqvx-8x2r-w74f

Опубликовано: 06 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.19.0 does not have proper authorisation checks in some of its REST endpoints, allowing users with a role as low as contributor to call them and inject arbitrary CSS in arbitrary saved layouts

The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.19.0 does not have proper authorisation checks in some of its REST endpoints, allowing users with a role as low as contributor to call them and inject arbitrary CSS in arbitrary saved layouts

EPSS

Процентиль: 34%
0.00141
Низкий

8.8 High

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 5.4
nvd
больше 3 лет назад

The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.19.0 does not have proper authorisation checks in some of its REST endpoints, allowing users with a role as low as contributor to call them and inject arbitrary CSS in arbitrary saved layouts

EPSS

Процентиль: 34%
0.00141
Низкий

8.8 High

CVSS3

Дефекты

CWE-863