Описание
The Login with phone number WordPress plugin before 1.3.7 includes a file delete.php with no form of authentication or authorization checks placed in the plugin directory, allowing unauthenticated user to remotely delete the plugin files leading to a potential Denial of Service situation.
Ссылки
- Third Party Advisory
- ExploitThird Party Advisory
- Third Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.3.7 (исключая)
cpe:2.3:a:idehweb:login_with_phone_number:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 67%
0.00539
Низкий
6.5 Medium
CVSS3
6.4 Medium
CVSS2
Дефекты
CWE-73
Связанные уязвимости
CVSS3: 6.5
github
почти 4 года назад
The Login with phone number WordPress plugin before 1.3.7 includes a file delete.php with no form of authentication or authorization checks placed in the plugin directory, allowing unauthenticated user to remotely delete the plugin files leading to a potential Denial of Service situation.
EPSS
Процентиль: 67%
0.00539
Низкий
6.5 Medium
CVSS3
6.4 Medium
CVSS2
Дефекты
CWE-73