Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-25084

Опубликовано: 07 фев. 2022
Источник: nvd
CVSS3: 4.3
CVSS2: 4
EPSS Низкий

Описание

The Advanced Cron Manager WordPress plugin before 2.4.2 and Advanced Cron Manager Pro WordPress plugin before 2.5.3 do not have authorisation checks in some of their AJAX actions, allowing any authenticated users, such as subscriber to call them and add or remove events as well as schedules for example

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:bracketspace:advanced_cron_manager:*:*:*:*:-:wordpress:*:*
Версия до 2.4.2 (исключая)
cpe:2.3:a:bracketspace:advanced_cron_manager:*:*:*:*:pro:wordpress:*:*
Версия до 2.5.3 (исключая)

EPSS

Процентиль: 38%
0.0017
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-862
CWE-862

Связанные уязвимости

github
около 4 лет назад

The Advanced Cron Manager WordPress plugin before 2.4.2, advanced-cron-manager-pro WordPress plugin before 2.5.3 does not have authorisation checks in some of its AJAX actions, allowing any authenticated users, such as subscriber to call them and add or remove events as well as schedules for example

EPSS

Процентиль: 38%
0.0017
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-862
CWE-862