Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-24635

Опубликовано: 20 сент. 2021
Источник: nvd
CVSS3: 5.4
CVSS2: 5.5
EPSS Низкий

Описание

The Visual Link Preview WordPress plugin before 2.2.3 does not enforce authorisation on several AJAX actions and has the CSRF nonce displayed for all authenticated users, allowing any authenticated user (such as subscriber) to call them and 1) Get and search through title and content of Draft post, 2) Get title of a password-protected post as well as 3) Upload an image from an URL

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:bootstrapped:visual_link_preview:*:*:*:*:*:wordpress:*:*
Версия до 2.2.3 (исключая)

EPSS

Процентиль: 40%
0.00179
Низкий

5.4 Medium

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-284
CWE-862

Связанные уязвимости

CVSS3: 5.4
github
около 3 лет назад

The Visual Link Preview WordPress plugin before 2.2.3 does not enforce authorisation on several AJAX actions and has the CSRF nonce displayed for all authenticated users, allowing any authenticated user (such as subscriber) to call them and 1) Get and search through title and content of Draft post, 2) Get title of a password-protected post as well as 3) Upload an image from an URL

EPSS

Процентиль: 40%
0.00179
Низкий

5.4 Medium

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-284
CWE-862