Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-2108

Опубликовано: 18 июл. 2022
Источник: nvd
CVSS3: 6.5
CVSS3: 5.3
EPSS Низкий

Описание

The plugin Wbcom Designs – BuddyPress Group Reviews for WordPress is vulnerable to unauthorized settings changes and review modification due to missing capability checks and improper nonce checks in several functions related to said actions in versions up to, and including, 2.8.3. This makes it possible for unauthenticated attackers to modify reviews and plugin settings on the affected site.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:wbcomdesigns:buddypress_group_reviews:*:*:*:*:*:wordpress:*:*
Версия до 2.8.4 (исключая)

EPSS

Процентиль: 71%
0.00693
Низкий

6.5 Medium

CVSS3

5.3 Medium

CVSS3

Дефекты

CWE-862
CWE-862

Связанные уязвимости

CVSS3: 5.3
github
больше 3 лет назад

The plugin Wbcom Designs – BuddyPress Group Reviews for WordPress is vulnerable to unauthorized settings changes and review modification due to missing capability checks and improper nonce checks in several functions related to said actions in versions up to, and including, 2.8.3. This makes it possible for unauthenticated attackers to modify reviews and plugin settings on the affected site.

EPSS

Процентиль: 71%
0.00693
Низкий

6.5 Medium

CVSS3

5.3 Medium

CVSS3

Дефекты

CWE-862
CWE-862