Описание
The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does not properly sanitise attacker-supplied data before using it in a SQL query, allowing any authenticated user, including Subscribers, to perform SQL injection attacks.
EPSS
Процентиль: 12%
0.00215
Низкий
8.1 High
CVSS3
Дефекты
CWE-89
Связанные уязвимости
CVSS3: 8.1
github
около 1 месяца назад
The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does not properly sanitise attacker-supplied data before using it in a SQL query, allowing any authenticated user, including Subscribers, to perform SQL injection attacks.
EPSS
Процентиль: 12%
0.00215
Низкий
8.1 High
CVSS3
Дефекты
CWE-89