Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-24195

Опубликовано: 14 мая 2021
Источник: nvd
CVSS3: 8.8
CVSS2: 6.5
EPSS Низкий

Описание

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login as User or Customer (User Switching) WordPress plugin before 1.8, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:wp-buy:login_as_user_or_customer_\(user_switching\):*:*:*:*:*:wordpress:*:*
Версия до 1.8 (исключая)

EPSS

Процентиль: 69%
0.00626
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-285
NVD-CWE-Other

Связанные уязвимости

CVSS3: 8.8
github
около 3 лет назад

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login as User or Customer (User Switching) WordPress plugin before 1.8, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

EPSS

Процентиль: 69%
0.00626
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-285
NVD-CWE-Other