Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-12535

Опубликовано: 07 янв. 2025
Источник: nvd
CVSS3: 8.6
EPSS Средний

Описание

The Host PHP Info plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when including the 'phpinfo' function in all versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to read configuration settings and predefined variables on the site's server. The plugin does not need to be activated for the vulnerability to be exploited.

EPSS

Процентиль: 94%
0.12453
Средний

8.6 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 8.6
github
около 1 года назад

The Host PHP Info plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when including the 'phpinfo' function in all versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to read configuration settings and predefined variables on the site's server. The plugin does not need to be activated for the vulnerability to be exploited.

EPSS

Процентиль: 94%
0.12453
Средний

8.6 High

CVSS3

Дефекты

CWE-862