Описание
The Automatic User Roles Switcher WordPress plugin before 1.1.2 does not have authorisation and proper CSRF checks, allowing any authenticated users like subscriber to add any role to themselves, such as administrator
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.1.2 (исключая)
cpe:2.3:a:addify:automatic_user_roles_switcher:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 41%
0.00188
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-269
Связанные уязвимости
CVSS3: 6.5
github
больше 3 лет назад
The Automatic User Roles Switcher WordPress plugin before 1.1.2 does not have authorisation and proper CSRF checks, allowing any authenticated users like subscriber to add any role to themselves, such as administrator
EPSS
Процентиль: 41%
0.00188
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-269