Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-0594

Опубликовано: 25 июл. 2022
Источник: nvd
CVSS3: 5.3
EPSS Средний

Описание

The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper authorisation check in one of the AJAX action, available to unauthenticated (in v < 9.7.5) and author+ (in v9.7.5) users, allowing them to call it and retrieve various information such as the list of active plugins, various version like PHP, cURL, WP etc.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:shareaholic:shareaholic:*:*:*:*:*:wordpress:*:*
Версия до 9.7.6 (исключая)

EPSS

Процентиль: 97%
0.43978
Средний

5.3 Medium

CVSS3

Дефекты

CWE-863
CWE-863

Связанные уязвимости

CVSS3: 5.3
github
больше 3 лет назад

The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper authorisation check in one of the AJAX action, available to unauthenticated (in v < 9.7.5) and author+ (in v9.7.5) users, allowing them to call it and retrieve various information such as the list of active plugins, various version like PHP, cURL, WP etc.

EPSS

Процентиль: 97%
0.43978
Средний

5.3 Medium

CVSS3

Дефекты

CWE-863
CWE-863