Описание
The Profile Builder WordPress plugin before 3.9.8 lacks authorisation and CSRF in its page creation function which allows unauthenticated users to create the register, log-in and edit-profile pages from the plugin on the blog
Ссылки
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.9.8 (исключая)
cpe:2.3:a:cozmoslabs:profile_builder:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 34%
0.00134
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-352
Связанные уязвимости
CVSS3: 4.3
github
больше 2 лет назад
The Profile Builder WordPress plugin before 3.9.8 lacks authorisation and CSRF in its page creation function which allows unauthenticated users to create the register, log-in and edit-profile pages from the plugin on the blog
EPSS
Процентиль: 34%
0.00134
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-352