Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-3460

Опубликовано: 04 июл. 2023
Источник: nvd
CVSS3: 9.8
EPSS Критический

Описание

The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create administrator accounts at will. This is actively being exploited in the wild.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ultimatemember:ultimate_member:*:*:*:*:*:wordpress:*:*
Версия до 2.6.7 (исключая)

EPSS

Процентиль: 100%
0.92971
Критический

9.8 Critical

CVSS3

Дефекты

Связанные уязвимости

CVSS3: 9.8
github
больше 2 лет назад

The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create administrator accounts at will. This is actively being exploited in the wild.

EPSS

Процентиль: 100%
0.92971
Критический

9.8 Critical

CVSS3

Дефекты