Описание
The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to disclose the site's user list and unpublished listings belonging to other users.
EPSS
Процентиль: 12%
0.00219
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-200
Связанные уязвимости
CVSS3: 6.5
github
28 дней назад
The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to disclose the site's user list and unpublished listings belonging to other users.
EPSS
Процентиль: 12%
0.00219
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-200