Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-0556

Опубликовано: 27 янв. 2023
Источник: nvd
CVSS3: 9.8
CVSS3: 6.5
EPSS Низкий

Описание

The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several functions in versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to obtain the blog metadata (via the function cstu_get_metadata) that includes the plugin's contentstudio_token. Knowing this token allows for other interactions with the plugin such as creating posts in versions prior to 1.2.5, which added other requirements to posting and updating.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:contentstudio:contentstudio:*:*:*:*:*:wordpress:*:*
Версия до 1.2.6 (исключая)

EPSS

Процентиль: 78%
0.0117
Низкий

9.8 Critical

CVSS3

6.5 Medium

CVSS3

Дефекты

Связанные уязвимости

CVSS3: 6.5
github
около 3 лет назад

The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several functions in versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to obtain the blog metadata (via the function cstu_get_metadata) that includes the plugin's contentstudio_token. Knowing this token allows for other interactions with the plugin such as creating posts in versions prior to 1.2.5, which added other requirements to posting and updating.

EPSS

Процентиль: 78%
0.0117
Низкий

9.8 Critical

CVSS3

6.5 Medium

CVSS3

Дефекты