Описание
The AAWP WordPress plugin before 3.12.3 can be used to abuse trusted domains to load malware or other files through it (Reflected File Download) to bypass firewall rules in companies.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.12.3 (исключая)
cpe:2.3:a:getaawp:amazon_affiliate_wordpress_plugin:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 70%
0.00655
Низкий
7.5 High
CVSS3
Дефекты
Связанные уязвимости
CVSS3: 7.5
github
около 3 лет назад
The AAWP WordPress plugin before 3.12.3 can be used to abuse trusted domains to load malware or other files through it (Reflected File Download) to bypass firewall rules in companies.
EPSS
Процентиль: 70%
0.00655
Низкий
7.5 High
CVSS3