Описание
The ArtPlacer Widget WordPress plugin before 2.21.2 does not have authorisation check in place when deleting widgets, allowing ay authenticated users, such as subscriber, to delete arbitrary widgets
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.21.1 (включая)
cpe:2.3:a:artplacer:artplacer_widget:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 39%
0.00178
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-862
Связанные уязвимости
CVSS3: 6.5
github
больше 1 года назад
The ArtPlacer Widget WordPress plugin before 2.21.2 does not have authorisation check in place when deleting widgets, allowing ay authenticated users, such as subscriber, to delete arbitrary widgets
EPSS
Процентиль: 39%
0.00178
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-862