Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xqw2-vwjg-w56m

Опубликовано: 12 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

The Zonify WordPress plugin before 1.0.5 does not perform any capability or authentication check before returning the site's stored account login token, allowing unauthenticated attackers to retrieve it and authenticate to the site owner's linked service account.

The Zonify WordPress plugin before 1.0.5 does not perform any capability or authentication check before returning the site's stored account login token, allowing unauthenticated attackers to retrieve it and authenticate to the site owner's linked service account.

EPSS

Процентиль: 22%
0.00288
Низкий

7.5 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.5
nvd
12 дней назад

The Zonify WordPress plugin before 1.0.5 does not perform any capability or authentication check before returning the site's stored account login token, allowing unauthenticated attackers to retrieve it and authenticate to the site owner's linked service account.

EPSS

Процентиль: 22%
0.00288
Низкий

7.5 High

CVSS3

Дефекты

CWE-200