Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

EPSS

Процентиль: 53%
0.003
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 6.5
github
около 1 года назад

The ELEX WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the elex_dp_export_rules() and elex_dp_import_rules() functions in all versions up to, and including, 2.1.7. This makes it possible for unauthenticated attackers to import and export product rules along with obtaining phpinfo() data

EPSS

Процентиль: 53%
0.003
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-862