Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x56p-hv7c-cxvx

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, the lack of capability checks and insufficient nonce check on the AJAX actions, simple301redirects/admin/get_wildcard and simple301redirects/admin/wildcard, made it possible for authenticated users to retrieve and update the wildcard value for redirects.

In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, the lack of capability checks and insufficient nonce check on the AJAX actions, simple301redirects/admin/get_wildcard and simple301redirects/admin/wildcard, made it possible for authenticated users to retrieve and update the wildcard value for redirects.

EPSS

Процентиль: 45%
0.0023
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-284
CWE-862

Связанные уязвимости

CVSS3: 4.3
nvd
больше 4 лет назад

In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, the lack of capability checks and insufficient nonce check on the AJAX actions, simple301redirects/admin/get_wildcard and simple301redirects/admin/wildcard, made it possible for authenticated users to retrieve and update the wildcard value for redirects.

EPSS

Процентиль: 45%
0.0023
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-284
CWE-862