Описание
The Chained Products WordPress plugin before 2.12.0 does not have authorisation and CSRF checks, as well as does not ensure that the option to be updated belong to the plugin, allowing unauthenticated attackers to set arbitrary options to 'no'
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.12.0 (исключая)
cpe:2.3:a:chained_products_project:chained_products:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 73%
0.00784
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-352
Связанные уязвимости
CVSS3: 4.3
github
около 3 лет назад
The Chained Products WordPress plugin before 2.12.0 does not have authorisation and CSRF checks, as well as does not ensure that the option to be updated belong to the plugin, allowing unauthenticated attackers to set arbitrary options to 'no'
EPSS
Процентиль: 73%
0.00784
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-352