Описание
The Decent Comments WordPress plugin before 3.0.2 does not restrict access to comment author email addresses and post author email addresses via its REST API endpoint, allowing unauthenticated attackers to enumerate registered user email addresses.
EPSS
Процентиль: 19%
0.00271
Низкий
5.8 Medium
CVSS3
Дефекты
Связанные уязвимости
CVSS3: 5.8
github
3 месяца назад
The Decent Comments WordPress plugin before 3.0.2 does not restrict access to comment author email addresses and post author email addresses via its REST API endpoint, allowing unauthenticated attackers to enumerate registered user email addresses.
EPSS
Процентиль: 19%
0.00271
Низкий
5.8 Medium
CVSS3