Описание
The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.18.0 does not have proper authorisation checks in some of its REST endpoints, allowing unauthenticated users to call them and inject arbitrary CSS in arbitrary saved layouts
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.18.0 (исключая)
cpe:2.3:a:visualportfolio:visual_portfolio\,_photo_gallery_\&_post_grid:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 66%
0.00519
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-862
Связанные уязвимости
CVSS3: 6.1
github
больше 3 лет назад
The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.18.0 does not have proper authorisation checks in some of its REST endpoints, allowing unauthenticated users to call them and inject arbitrary CSS in arbitrary saved layouts
EPSS
Процентиль: 66%
0.00519
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-862