Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-0865

Опубликовано: 20 мар. 2023
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

The WooCommerce Multiple Customer Addresses & Shipping WordPress plugin before 21.7 does not ensure that the address to add/update/retrieve/delete and duplicate belong to the user making the request, or is from a high privilege users, allowing any authenticated users, such as subscriber to add/update/duplicate/delete as well as retrieve addresses of other users.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:woocommerce_multiple_customer_addresses_\&_shipping_project:woocommerce_multiple_customer_addresses_\&_shipping:*:*:*:*:*:wordpress:*:*
Версия до 21.7 (исключая)

EPSS

Процентиль: 89%
0.04322
Низкий

8.8 High

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 8.8
github
почти 3 года назад

The WooCommerce Multiple Customer Addresses & Shipping WordPress plugin before 21.7 does not ensure that the address to add/update/retrieve/delete and duplicate belong to the user making the request, or is from a high privilege users, allowing any authenticated users, such as subscriber to add/update/duplicate/delete as well as retrieve addresses of other users.

EPSS

Процентиль: 89%
0.04322
Низкий

8.8 High

CVSS3

Дефекты

CWE-639