Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wv57-f2gm-36vc

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php. Any attacker who knows the username of an administrator can log in.

The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php. Any attacker who knows the username of an administrator can log in.

EPSS

Процентиль: 100%
0.9355
Критический

Связанные уязвимости

CVSS3: 9.8
nvd
около 6 лет назад

The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php. Any attacker who knows the username of an administrator can log in.

EPSS

Процентиль: 100%
0.9355
Критический