Описание
The Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the attendees list on any post type regardless of status. (e.g. draft, private, pending review, password-protected, and trashed posts).
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 5.9.1 (исключая)
cpe:2.3:a:liquidweb:event_tickets:*:*:*:*:plus:wordpress:*:*
EPSS
Процентиль: 35%
0.00142
Низкий
4.3 Medium
CVSS3
Дефекты
NVD-CWE-noinfo
Связанные уязвимости
CVSS3: 4.3
github
почти 2 года назад
The Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the attendees list on any post type regardless of status. (e.g. draft, private, pending review, password-protected, and trashed posts).
EPSS
Процентиль: 35%
0.00142
Низкий
4.3 Medium
CVSS3
Дефекты
NVD-CWE-noinfo