Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-4239

Опубликовано: 26 дек. 2022
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

The Workreap WordPress theme before 2.6.4 does not verify that an addon service belongs to the user issuing the request, or indeed that it is an addon service, when processing the workreap_addons_service_remove action, allowing any user to delete any post by knowing or guessing the id.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:amentotech:workreap:*:*:*:*:*:wordpress:*:*
Версия до 2.6.4 (исключая)

EPSS

Процентиль: 41%
0.0019
Низкий

6.5 Medium

CVSS3

Дефекты

Связанные уязвимости

CVSS3: 6.5
github
около 3 лет назад

The Workreap WordPress theme before 2.6.4 does not verify that an addon service belongs to the user issuing the request, or indeed that it is an addon service, when processing the workreap_addons_service_remove action, allowing any user to delete any post by knowing or guessing the id.

EPSS

Процентиль: 41%
0.0019
Низкий

6.5 Medium

CVSS3

Дефекты