Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-6434

Опубликовано: 04 июл. 2024
Источник: nvd
CVSS3: 3.1
CVSS3: 4.3
EPSS Низкий

Описание

The Premium Addons for Elementor plugin for WordPress is vulnerable to Regular Expression Denial of Service (ReDoS) in all versions up to, and including, 4.10.35. This is due to processing user-supplied input as a regular expression. This makes it possible for authenticated attackers, with Author-level access and above, to create and query a malicious post title, resulting in slowing server resources.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:leap13:premium_addons_for_elementor:*:*:*:*:*:wordpress:*:*
Версия до 4.10.36 (исключая)

EPSS

Процентиль: 25%
0.00087
Низкий

3.1 Low

CVSS3

4.3 Medium

CVSS3

Дефекты

CWE-1333

Связанные уязвимости

CVSS3: 3.1
github
больше 1 года назад

The Premium Addons for Elementor plugin for WordPress is vulnerable to Regular Expression Denial of Service (ReDoS) in all versions up to, and including, 4.10.35. This is due to processing user-supplied input as a regular expression. This makes it possible for authenticated attackers, with Author-level access and above, to create and query a malicious post title, resulting in slowing server resources.

EPSS

Процентиль: 25%
0.00087
Низкий

3.1 Low

CVSS3

4.3 Medium

CVSS3

Дефекты

CWE-1333