Описание
The Herd Effects WordPress plugin before 5.2.4 does not have CSRF when deleting its items, which could allow attackers to make logged in admins delete arbitrary effects via a CSRF attack
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 5.2.4 (исключая)
cpe:2.3:a:wow-company:herd_effects:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 21%
0.00067
Низкий
4.3 Medium
CVSS3
Дефекты
Связанные уязвимости
CVSS3: 4.3
github
больше 2 лет назад
The Herd Effects WordPress plugin before 5.2.4 does not have CSRF when deleting its items, which could allow attackers to make logged in admins delete arbitrary effects via a CSRF attack
EPSS
Процентиль: 21%
0.00067
Низкий
4.3 Medium
CVSS3