Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-4792

Опубликовано: 07 сент. 2023
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

The Duplicate Post Page Menu & Custom Post Type plugin for WordPress is vulnerable to unauthorized page and post duplication due to a missing capability check on the duplicate_ppmc_post_as_draft function in versions up to, and including, 2.3.1. This makes it possible for authenticated attackers with subscriber access or higher to duplicate posts and pages.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:inqsys:duplicate_post_page_menu_\&_custom_post_type:*:*:*:*:*:wordpress:*:*
Версия до 2.3.1 (включая)

EPSS

Процентиль: 23%
0.00073
Низкий

4.3 Medium

CVSS3

Дефекты

Связанные уязвимости

CVSS3: 4.3
github
больше 2 лет назад

The Duplicate Post Page Menu & Custom Post Type plugin for WordPress is vulnerable to unauthorized page and post duplication due to a missing capability check on the duplicate_ppmc_post_as_draft function in versions up to, and including, 2.3.1. This makes it possible for authenticated attackers with subscriber access or higher to duplicate posts and pages.

EPSS

Процентиль: 23%
0.00073
Низкий

4.3 Medium

CVSS3

Дефекты