Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-2083

Опубликовано: 09 июн. 2023
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the save function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to save plugin settings. While a nonce check is present, it is only executed when a nonce is provided. Not providing a nonce results in the nonce verification to be skipped. There is no capability check.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:wpdeveloper:essential_blocks:*:*:*:*:*:wordpress:*:*
Версия до 4.0.6 (включая)

EPSS

Процентиль: 23%
0.00076
Низкий

4.3 Medium

CVSS3

Дефекты

Связанные уязвимости

CVSS3: 4.3
github
больше 2 лет назад

The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the save function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to save plugin settings. While a nonce check is present, it is only executed when a nonce is provided. Not providing a nonce results in the nonce verification to be skipped. There is no capability check.

EPSS

Процентиль: 23%
0.00076
Низкий

4.3 Medium

CVSS3

Дефекты