Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-4917

Опубликовано: 13 сент. 2023
Источник: nvd
CVSS3: 5.3
CVSS3: 6.5
EPSS Низкий

Описание

The Leyka plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.30.3 via the 'leyka_ajax_get_env_and_options' function. This can allow authenticated attackers with subscriber-level permissions or above to extract sensitive data including Sberbank API key and password, PayPal Client Secret, and more keys and passwords.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:te-st:leyka:*:*:*:*:*:wordpress:*:*
Версия до 3.30.3 (включая)

EPSS

Процентиль: 60%
0.00401
Низкий

5.3 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

Связанные уязвимости

CVSS3: 5.3
github
больше 2 лет назад

The Leyka plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.30.3 via the 'leyka_ajax_get_env_and_options' function. This can allow authenticated attackers with subscriber-level permissions or above to extract sensitive data including Sberbank API key and password, PayPal Client Secret, and more keys and passwords.

EPSS

Процентиль: 60%
0.00401
Низкий

5.3 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты