Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-3244

Опубликовано: 17 авг. 2023
Источник: nvd
CVSS3: 5.3
CVSS3: 4.3
EPSS Низкий

Описание

The Comments Like Dislike plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the restore_settings function called via an AJAX action in versions up to, and including, 1.1.9. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to reset the plugin's settings. NOTE: After attempting to contact the developer with no response, and reporting this to the WordPress plugin's team 30 days ago we are disclosing this issue as it still is not updated.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:wphappycoders:comments_like_dislike:*:*:*:*:*:wordpress:*:*
Версия до 1.1.9 (включая)

EPSS

Процентиль: 88%
0.03814
Низкий

5.3 Medium

CVSS3

4.3 Medium

CVSS3

Дефекты

Связанные уязвимости

CVSS3: 5.3
github
больше 2 лет назад

The Comments Like Dislike plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the restore_settings function called via an AJAX action in versions up to, and including, 1.1.9. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to reset the plugin's settings. NOTE: After attempting to contact the developer with no response, and reporting this to the WordPress plugin's team 30 days ago we are disclosing this issue as it still is not updated.

CVSS3: 4.3
fstec
больше 2 лет назад

Уязвимость функции restore_settings плагина Comments Like Dislike системы управления содержимым сайта WordPress, позволяющая нарушителю оказать воздействие на целостность данных

EPSS

Процентиль: 88%
0.03814
Низкий

5.3 Medium

CVSS3

4.3 Medium

CVSS3

Дефекты