Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-6397

Опубликовано: 11 июл. 2024
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 0.1.0.44. This is due to insufficient verification of the API key. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the username, and to perform a variety of other administrative tasks. NOTE: This vulnerability was partially fixed in 0.1.0.44, but was still exploitable via Cross-Site Request Forgery.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:instawp:instawp_connect:*:*:*:*:*:wordpress:*:*
Версия до 0.1.0.45 (исключая)

EPSS

Процентиль: 69%
0.00585
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.8
github
больше 1 года назад

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 0.1.0.44. This is due to insufficient verification of the API key. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the username, and to perform a variety of other administrative tasks. NOTE: This vulnerability was partially fixed in 0.1.0.44, but was still exploitable via Cross-Site Request Forgery.

EPSS

Процентиль: 69%
0.00585
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287