Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-13307

Опубликовано: 19 дек. 2025
Источник: nvd
CVSS3: 7.2
EPSS Низкий

Описание

The Ocean Modal Window WordPress plugin before 2.3.3 is vulnerable to Remote Code Execution via the modal display logic. These modals can be displayed under user-controlled conditions that Editors and Administrators can set (edit_pages capability). The conditions are then executed as part of an eval statement executed on every site page. This leads to remote code execution.

EPSS

Процентиль: 56%
0.00332
Низкий

7.2 High

CVSS3

Дефекты

Связанные уязвимости

CVSS3: 6.5
github
около 2 месяцев назад

The Ocean Modal Window WordPress plugin before 2.3.3 is vulnerable to Remote Code Execution via the modal display logic. These modals can be displayed under user-controlled conditions that Editors and Administrators can set (edit_pages capability). The conditions are then executed as part of an eval statement executed on every site page. This leads to remote code execution.

EPSS

Процентиль: 56%
0.00332
Низкий

7.2 High

CVSS3

Дефекты