Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-25087

Опубликовано: 07 мар. 2022
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticated attackers to call them, which could lead to sensitive information disclosure, such as posts passwords (fixed in 3.2.24) and files Master Keys (fixed in 3.2.25).

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:w3eden:download_manager:*:*:*:*:*:wordpress:*:*
Версия до 3.2.35 (исключая)

EPSS

Процентиль: 81%
0.01573
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-862
CWE-862

Связанные уязвимости

CVSS3: 7.5
github
почти 4 года назад

The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticated attackers to call them, which could lead to sensitive information disclosure, such as posts passwords (fixed in 3.2.24) and files Master Keys (fixed in 3.2.25).

EPSS

Процентиль: 81%
0.01573
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-862
CWE-862