Описание
The Flynax Bridge plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the deleteUser() function in all versions up to, and including, 2.2.0. This makes it possible for unauthenticated attackers to delete arbitrary users.
Уязвимые конфигурации
Конфигурация 1Версия до 2.2.0 (включая)
cpe:2.3:a:flynax:flynax_bridge:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 25%
0.00325
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-862
CWE-862
Связанные уязвимости
CVSS3: 5.3
github
около 1 года назад
The Flynax Bridge plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the deleteUser() function in all versions up to, and including, 2.2.0. This makes it possible for unauthenticated attackers to delete arbitrary users.
EPSS
Процентиль: 25%
0.00325
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-862
CWE-862