Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-4004

Опубликовано: 12 дек. 2022
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

The Donation Button WordPress plugin through 4.0.0 does not properly check for privileges and nonce tokens in its "donation_button_twilio_send_test_sms" AJAX action, which may allow any users with an account on the affected site, like subscribers, to use the plugin's Twilio integration to send SMSes to arbitrary phone numbers.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:donation_button_project:donation_button:*:*:*:*:*:wordpress:*:*
Версия до 4.0.0 (включая)

EPSS

Процентиль: 36%
0.00153
Низкий

4.3 Medium

CVSS3

Дефекты

Связанные уязвимости

CVSS3: 4.3
github
около 3 лет назад

The Donation Button WordPress plugin through 4.0.0 does not properly check for privileges and nonce tokens in its "donation_button_twilio_send_test_sms" AJAX action, which may allow any users with an account on the affected site, like subscribers, to use the plugin's Twilio integration to send SMSes to arbitrary phone numbers.

EPSS

Процентиль: 36%
0.00153
Низкий

4.3 Medium

CVSS3

Дефекты