Описание
The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints, allowing any authenticated user (Subscriber+) to read, modify, or delete other users' private messages.
EPSS
Процентиль: 4%
0.00138
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-639
Связанные уязвимости
CVSS3: 5.4
github
3 дня назад
The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints, allowing any authenticated user (Subscriber+) to read, modify, or delete other users' private messages.
EPSS
Процентиль: 4%
0.00138
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-639