Описание
The Intuitive Custom Post Order WordPress plugin before 3.1.4 does not check for authorization in the update-menu-order ajax action, allowing any logged in user (with roles as low as Subscriber) to update the menu order
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.1.4 (исключая)
cpe:2.3:a:intuitive_custom_post_order_project:intuitive_custom_post_order:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 25%
0.00085
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-862
Связанные уязвимости
CVSS3: 4.3
github
почти 3 года назад
The Intuitive Custom Post Order WordPress plugin through 3.1.3 does not check for authorization in the update-menu-order ajax action, allowing any logged in user (with roles as low as Subscriber) to update the menu order
EPSS
Процентиль: 25%
0.00085
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-862