Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-13798

Опубликовано: 22 фев. 2025
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to unauthorized order creation in all versions up to, and including, 2.3.5. This is due to insufficient verification on form fields. This makes it possible for unauthenticated attackers to create new orders for products and mark them as paid without actually completing a payment.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:pickplugins:comboblocks:*:*:*:*:*:wordpress:*:*
Версия до 2.3.6 (исключая)

EPSS

Процентиль: 60%
0.00401
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-20
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 5.3
github
12 месяцев назад

The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to unauthorized order creation in all versions up to, and including, 2.3.5. This is due to insufficient verification on form fields. This makes it possible for unauthenticated attackers to create new orders for products and mark them as paid without actually completing a payment.

EPSS

Процентиль: 60%
0.00401
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-20
NVD-CWE-noinfo