Описание
The Brizy plugin for WordPress is vulnerable to authorization bypass due to a incorrect capability check on the is_administrator() function in versions up to, and including, 1.0.125. This makes it possible for authenticated attackers to access and interact with available AJAX functions.
Ссылки
- ExploitThird Party Advisory
- Third Party Advisory
- ExploitThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.0.125 (включая)
cpe:2.3:a:brizy:brizy:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 35%
0.00143
Низкий
7.4 High
CVSS3
8.1 High
CVSS3
Дефекты
CWE-863
Связанные уязвимости
CVSS3: 7.4
github
больше 2 лет назад
The Brizy plugin for WordPress is vulnerable to authorization bypass due to a incorrect capability check on the is_administrator() function in versions up to, and including, 1.0.125. This makes it possible for authenticated attackers to access and interact with available AJAX functions.
EPSS
Процентиль: 35%
0.00143
Низкий
7.4 High
CVSS3
8.1 High
CVSS3
Дефекты
CWE-863