Описание
The Advanced Cron Manager WordPress plugin before 2.4.2 and Advanced Cron Manager Pro WordPress plugin before 2.5.3 do not have authorisation checks in some of their AJAX actions, allowing any authenticated users, such as subscriber to call them and add or remove events as well as schedules for example
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.4.2 (исключая)Версия до 2.5.3 (исключая)
Одно из
cpe:2.3:a:bracketspace:advanced_cron_manager:*:*:*:*:-:wordpress:*:*
cpe:2.3:a:bracketspace:advanced_cron_manager:*:*:*:*:pro:wordpress:*:*
EPSS
Процентиль: 38%
0.0017
Низкий
4.3 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-862
CWE-862
Связанные уязвимости
github
около 4 лет назад
The Advanced Cron Manager WordPress plugin before 2.4.2, advanced-cron-manager-pro WordPress plugin before 2.5.3 does not have authorisation checks in some of its AJAX actions, allowing any authenticated users, such as subscriber to call them and add or remove events as well as schedules for example
EPSS
Процентиль: 38%
0.0017
Низкий
4.3 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-862
CWE-862