Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-20714

Опубликовано: 15 янв. 2019
Источник: nvd
CVSS3: 8.1
CVSS2: 5.5
EPSS Низкий

Описание

The logging system of the Automattic WooCommerce plugin before 3.4.6 for WordPress is vulnerable to a File Deletion vulnerability. This allows deletion of woocommerce.php, which leads to certain privilege checks not being in place, and therefore a shop manager can escalate privileges to admin.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:woocommerce:woocommerce:*:*:*:*:*:wordpress:*:*
Версия до 3.4.6 (исключая)

EPSS

Процентиль: 80%
0.01392
Низкий

8.1 High

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.1
github
больше 3 лет назад

The logging system of the Automattic WooCommerce plugin before 3.4.6 for WordPress is vulnerable to a File Deletion vulnerability. This allows deletion of woocommerce.php, which leads to certain privilege checks not being in place, and therefore a shop manager can escalate privileges to admin.

EPSS

Процентиль: 80%
0.01392
Низкий

8.1 High

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-22