Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-4917

Опубликовано: 13 сент. 2023
Источник: nvd
CVSS3: 5.3
CVSS3: 6.5
EPSS Низкий

Описание

The Leyka plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.30.7 via the 'leyka_ajax_get_env_and_options' function. This can allow authenticated attackers with subscriber-level permissions or above to extract sensitive data including Sberbank API key and password, PayPal Client Secret, and more keys and passwords.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:te-st:leyka:*:*:*:*:*:wordpress:*:*
Версия до 3.30.3 (включая)

EPSS

Процентиль: 46%
0.0059
Низкий

5.3 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.3
github
почти 3 года назад

The Leyka plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.30.3 via the 'leyka_ajax_get_env_and_options' function. This can allow authenticated attackers with subscriber-level permissions or above to extract sensitive data including Sberbank API key and password, PayPal Client Secret, and more keys and passwords.

EPSS

Процентиль: 46%
0.0059
Низкий

5.3 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-200