Описание
The GPT AI Power: Content Writer & ChatGPT & Image Generator & WooCommerce Product Writer & AI Training WordPress plugin before 1.4.38 does not perform any kind of nonce or privilege checks before letting logged-in users modify arbitrary posts.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.4.38 (исключая)
cpe:2.3:a:gptaipower:gpt_ai_power:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 33%
0.0013
Низкий
4.3 Medium
CVSS3
5.4 Medium
CVSS3
Дефекты
Связанные уязвимости
CVSS3: 4.3
github
больше 2 лет назад
The GPT AI Power: Content Writer & ChatGPT & Image Generator & WooCommerce Product Writer & AI Training WordPress plugin before 1.4.38 does not perform any kind of nonce or privilege checks before letting logged-in users modify arbitrary posts.
EPSS
Процентиль: 33%
0.0013
Низкий
4.3 Medium
CVSS3
5.4 Medium
CVSS3