Описание
The WP VR WordPress plugin before 8.3.0 does not have authorisation and CSRF checks in various AJAX actions, one in particular could allow any authenticated users, such as subscriber to update arbitrary tours
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 8.3.0 (исключая)
cpe:2.3:a:rextheme:wp_vr:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 18%
0.00058
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-352
Связанные уязвимости
CVSS3: 4.3
github
почти 3 года назад
The WP VR WordPress plugin before 8.3.0 does not have authorisation and CSRF checks in various AJAX actions, one in particular could allow any authenticated users, such as subscriber to update arbitrary tours
EPSS
Процентиль: 18%
0.00058
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-352