Описание
The HM Multiple Roles WordPress plugin before 1.3 does not have any access control to prevent low privilege users to set themselves as admin via their profile page
Ссылки
- ExploitThird Party Advisory
- Third Party Advisory
- ExploitThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.3 (исключая)
cpe:2.3:a:hmplugin:hm_multiple_roles:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 71%
0.00659
Низкий
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-269
CWE-669
Связанные уязвимости
CVSS3: 8.8
github
больше 3 лет назад
The HM Multiple Roles WordPress plugin before 1.3 does not have any access control to prevent low privilege users to set themselves as admin via their profile page
EPSS
Процентиль: 71%
0.00659
Низкий
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-269
CWE-669