Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xh2m-j2x9-vffg

Опубликовано: 24 нояб. 2021
Источник: github
Github: Не прошло ревью
CVSS3: 5.7

Описание

The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwap_plugin_activate AJAX action, allowing any authenticated users, such as subscribers, to activate plugins that are already installed.

The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwap_plugin_activate AJAX action, allowing any authenticated users, such as subscribers, to activate plugins that are already installed.

EPSS

Процентиль: 32%
0.00124
Низкий

5.7 Medium

CVSS3

Дефекты

CWE-284
CWE-352

Связанные уязвимости

CVSS3: 5.7
nvd
около 4 лет назад

The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwap_plugin_activate AJAX action, allowing any authenticated users, such as subscribers, to activate plugins that are already installed.

EPSS

Процентиль: 32%
0.00124
Низкий

5.7 Medium

CVSS3

Дефекты

CWE-284
CWE-352