Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-39341

Опубликовано: 01 нояб. 2021
Источник: nvd
CVSS3: 8.2
CVSS2: 6.4
EPSS Средний

Описание

The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due to insufficient authorization validation via the logged_in_or_has_api_key function in the ~/OMAPI/RestApi.php file that can used to exploit inject malicious web scripts on sites with the plugin installed. This affects versions up to, and including, 2.6.4.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:optinmonster:optinmonster:*:*:*:*:*:wordpress:*:*
Версия до 2.6.4 (включая)

EPSS

Процентиль: 97%
0.44317
Средний

8.2 High

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-285
CWE-863

Связанные уязвимости

CVSS3: 8.2
github
больше 3 лет назад

The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due to insufficient authorization validation via the logged_in_or_has_api_key function in the ~/OMAPI/RestApi.php file that can used to exploit inject malicious web scripts on sites with the plugin installed. This affects versions up to, and including, 2.6.4.

EPSS

Процентиль: 97%
0.44317
Средний

8.2 High

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-285
CWE-863