Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-0764

Опубликовано: 28 фев. 2025
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

The wpForo Forum plugin for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'update' method of the 'Members' class in all versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with subscriber-level privileges or higher, to read arbitrary files on the server.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gvectors:wpforo_forum:*:*:*:*:*:wordpress:*:*
Версия до 2.4.2 (исключая)

EPSS

Процентиль: 36%
0.00154
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-20
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 6.5
github
11 месяцев назад

The wpForo Forum plugin for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'update' method of the 'Members' class in all versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with subscriber-level privileges or higher, to read arbitrary files on the server.

EPSS

Процентиль: 36%
0.00154
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-20
NVD-CWE-noinfo