Описание
The YaySMTP WordPress plugin before 2.2.1 does not have capability check in an AJAX action, allowing any logged in users, such as subscriber to view the Logs of the plugin
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.2.1 (исключая)
cpe:2.3:a:yaycommerce:yaysmtp:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 40%
0.00182
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-862
Связанные уязвимости
CVSS3: 4.3
github
больше 3 лет назад
The YaySMTP WordPress plugin before 2.2.1 does not have capability check in an AJAX action, allowing any logged in users, such as subscriber to view the Logs of the plugin
EPSS
Процентиль: 40%
0.00182
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-862