Описание
The Awesome Support WordPress plugin before 6.1.5 does not correctly authorize the wpas_edit_reply function, allowing users to edit posts for which they do not have permission.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 6.1.5 (исключая)
cpe:2.3:a:getawesomesupport:awesome_support:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 17%
0.00054
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-863
CWE-683
Связанные уязвимости
CVSS3: 4.3
github
больше 2 лет назад
The Awesome Support WordPress plugin before 6.1.5 does not correctly authorize the wpas_edit_reply function, allowing users to edit posts for which they do not have permission.
EPSS
Процентиль: 17%
0.00054
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-863
CWE-683