Описание
The Popup Manager WordPress plugin through 1.6.6 does not have authorisation and CSRF checks when deleting popups, which could allow unauthenticated users to delete them
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.6.6 (включая)
cpe:2.3:a:popup_manager_project:popup_manager:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 32%
0.0012
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-352
Связанные уязвимости
CVSS3: 4.3
github
около 3 лет назад
The Popup Manager WordPress plugin through 1.6.6 does not have authorisation and CSRF checks when deleting popups, which could allow unauthenticated users to delete them
EPSS
Процентиль: 32%
0.0012
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-352