Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xp5w-q4v3-mxrm

Опубликовано: 04 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handlers, allowing any authenticated user down to Subscriber to read the site's entire stored OpenAI prompt history.

The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handlers, allowing any authenticated user down to Subscriber to read the site's entire stored OpenAI prompt history.

EPSS

Процентиль: 6%
0.00162
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 4.3
nvd
8 дней назад

The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handlers, allowing any authenticated user down to Subscriber to read the site's entire stored OpenAI prompt history.

EPSS

Процентиль: 6%
0.00162
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862