Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-5304

Опубликовано: 28 июн. 2025
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

The PT Project Notebooks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization in the wpnb_pto_new_users_add() function in versions 1.0.0 through 1.1.3. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ptoffice:pt_project_notebooks:*:*:*:*:*:wordpress:*:*
Версия от 1.0.0 (включая) до 1.1.3 (включая)

EPSS

Процентиль: 51%
0.00279
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 9.8
github
7 месяцев назад

The PT Project Notebooks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization in the wpnb_pto_new_users_add() function in versions 1.0.0 through 1.1.3. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.

EPSS

Процентиль: 51%
0.00279
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-862