Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-6897

Опубликовано: 18 янв. 2017
Источник: nvd
CVSS3: 6.5
CVSS2: 4.3
EPSS Средний

Описание

Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 allows remote attackers to hijack the authentication of subscribers for /dev/random read operations by leveraging a late call to the check_ajax_referer function, a related issue to CVE-2016-6896.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*
Версия до 4.5.5 (включая)

EPSS

Процентиль: 96%
0.30259
Средний

6.5 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 8 лет назад

Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 allows remote attackers to hijack the authentication of subscribers for /dev/random read operations by leveraging a late call to the check_ajax_referer function, a related issue to CVE-2016-6896.

CVSS3: 6.5
debian
больше 8 лет назад

Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_ ...

CVSS3: 6.5
github
около 3 лет назад

Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 allows remote attackers to hijack the authentication of subscribers for /dev/random read operations by leveraging a late call to the check_ajax_referer function, a related issue to CVE-2016-6896.

EPSS

Процентиль: 96%
0.30259
Средний

6.5 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-352