Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-24968

Опубликовано: 24 янв. 2022
Источник: nvd
CVSS3: 5.7
CVSS2: 3.5
EPSS Низкий

Описание

The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq and ewd_ufaq_welcome_add_faq_page AJAX actions, available to any authenticated users. As a result, any users, with a role as low as Subscriber could create FAQ and FAQ questions

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:etoilewebdesign:ultimate_faq:*:*:*:*:*:wordpress:*:*
Версия до 2.1.2 (исключая)

EPSS

Процентиль: 26%
0.00092
Низкий

5.7 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-862
CWE-352

Связанные уязвимости

CVSS3: 5.7
github
около 4 лет назад

The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq and ewd_ufaq_welcome_add_faq_page AJAX actions, available to any authenticated users. As a result, any users, with a role as low as Subscriber could create FAQ and FAQ questions

EPSS

Процентиль: 26%
0.00092
Низкий

5.7 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-862
CWE-352