Описание
The Simple Author Box WordPress plugin before 2.52 does not verify a user ID before outputting information about that user, leading to arbitrary user information disclosure to users with a role as low as Contributor.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.52 (исключая)
cpe:2.3:a:webfactoryltd:simple_author_box:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 35%
0.00143
Низкий
4.3 Medium
CVSS3
Дефекты
Связанные уязвимости
CVSS3: 4.3
github
больше 2 лет назад
The Simple Author Box WordPress plugin before 2.52 does not verify a user ID before outputting information about that user, leading to arbitrary user information disclosure to users with a role as low as Contributor.
EPSS
Процентиль: 35%
0.00143
Низкий
4.3 Medium
CVSS3