Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-4360

Опубликовано: 07 июн. 2023
Источник: nvd
CVSS3: 9.9
CVSS3: 8.8
EPSS Низкий

Описание

The Controlled Admin Access plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.5 by not properly restricting access to the configuration page. This makes it possible for attackers to create a new administrator role with unrestricted access.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:wpruby:controlled_admin_access:*:*:*:*:*:wordpress:*:*
Версия до 1.5.5 (включая)

EPSS

Процентиль: 27%
0.00096
Низкий

9.9 Critical

CVSS3

8.8 High

CVSS3

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 9.9
github
больше 2 лет назад

The Controlled Admin Access plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.5 by not properly restricting access to the configuration page. This makes it possible for attackers to create a new administrator role with unrestricted access.

EPSS

Процентиль: 27%
0.00096
Низкий

9.9 Critical

CVSS3

8.8 High

CVSS3

Дефекты

NVD-CWE-noinfo