Описание
The Simple Photoswipe WordPress plugin through 0.1 does not have authorisation check when updating its settings, which could allow any authenticated users, such as subscriber to update them
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.1 (включая)
cpe:2.3:a:zitscher:simple_photoswipe:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 49%
0.00263
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-862
Связанные уязвимости
CVSS3: 6.5
github
больше 1 года назад
The Simple Photoswipe WordPress plugin through 0.1 does not have authorisation check when updating its settings, which could allow any authenticated users, such as subscriber to update them
EPSS
Процентиль: 49%
0.00263
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-862