Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x27x-7595-v3m5

Опубликовано: 31 окт. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

The PublishPress Capabilities WordPress plugin before 2.5.2, PublishPress Capabilities Pro WordPress plugin before 2.5.2 unserializes the content of imported files, which could lead to PHP object injection attacks by administrators, on multisite WordPress configurations. Successful exploitation in this case requires other plugins with a suitable gadget chain to be present on the site.

The PublishPress Capabilities WordPress plugin before 2.5.2, PublishPress Capabilities Pro WordPress plugin before 2.5.2 unserializes the content of imported files, which could lead to PHP object injection attacks by administrators, on multisite WordPress configurations. Successful exploitation in this case requires other plugins with a suitable gadget chain to be present on the site.

EPSS

Процентиль: 75%
0.00855
Низкий

7.2 High

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 7.2
nvd
больше 3 лет назад

The PublishPress Capabilities WordPress plugin before 2.5.2, PublishPress Capabilities Pro WordPress plugin before 2.5.2 unserializes the content of imported files, which could lead to PHP object injection attacks by administrators, on multisite WordPress configurations. Successful exploitation in this case requires other plugins with a suitable gadget chain to be present on the site.

EPSS

Процентиль: 75%
0.00855
Низкий

7.2 High

CVSS3

Дефекты

CWE-502