Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-1658

Опубликовано: 13 июн. 2022
Источник: nvd
CVSS3: 5.4
CVSS2: 5.5
EPSS Низкий

Описание

Vulnerable versions of the Jupiter Theme (<= 6.10.1) allow arbitrary plugin deletion by any authenticated user, including users with the subscriber role, via the abb_remove_plugin AJAX action registered in the framework/admin/control-panel/logic/plugin-management.php file. Using this functionality, any logged-in user can delete any installed plugin on the site.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:artbees:jupiter:*:*:*:*:*:wordpress:*:*
Версия до 6.10.1 (включая)

EPSS

Процентиль: 38%
0.00162
Низкий

5.4 Medium

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-284
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 5.4
github
больше 3 лет назад

Vulnerable versions of the Jupiter Theme (<= 6.10.1) allow arbitrary plugin deletion by any authenticated user, including users with the subscriber role, via the abb_remove_plugin AJAX action registered in the framework/admin/control-panel/logic/plugin-management.php file. Using this functionality, any logged-in user can delete any installed plugin on the site.

EPSS

Процентиль: 38%
0.00162
Низкий

5.4 Medium

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-284
NVD-CWE-noinfo