Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-36840

Опубликовано: 16 окт. 2024
Источник: nvd
CVSS3: 7.3
CVSS3: 9.8
EPSS Низкий

Описание

The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ajax_route_url() function called via a nopriv AJAX action in versions up to, and including, 2.3.8. This makes it possible for unauthenticated attackers to call that function and perform a wide variety of actions such as including random template, injecting malicious web scripts, and more.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:motopress:timetable_and_event_schedule:*:*:*:*:*:wordpress:*:*
Версия до 2.3.9 (исключая)

EPSS

Процентиль: 50%
0.00266
Низкий

7.3 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 7.3
github
больше 1 года назад

The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ajax_route_url() function called via a nopriv AJAX action in versions up to, and including, 2.3.8. This makes it possible for unauthenticated attackers to call that function and perform a wide variety of actions such as including random template, injecting malicious web scripts, and more.

EPSS

Процентиль: 50%
0.00266
Низкий

7.3 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-862