Описание
The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which executes user-supplied PHP code, allowing any authenticated user, such as a subscriber, to run arbitrary code on the server.
EPSS
Процентиль: 21%
0.00288
Низкий
9.9 Critical
CVSS3
Дефекты
CWE-94
Связанные уязвимости
CVSS3: 9.9
github
16 дней назад
The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which executes user-supplied PHP code, allowing any authenticated user, such as a subscriber, to run arbitrary code on the server.
CVSS3: 9.9
fstec
18 дней назад
Уязвимость консоли отладки плагина WatchMan-Site7 системы управления содержимым сайта WordPress, позволяющая нарушителю выполнить произвольный код
EPSS
Процентиль: 21%
0.00288
Низкий
9.9 Critical
CVSS3
Дефекты
CWE-94