Описание
The Really Simple Security WordPress plugin before 9.8.3 does not validate a client-supplied address value before using it as a storage key in one of its own options, allowing unauthenticated attackers to grow that option without bound and to slow the site's handling of missing pages.
EPSS
Процентиль: 16%
0.00248
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-400
Связанные уязвимости
CVSS3: 5.3
github
6 дней назад
The Really Simple Security WordPress plugin before 9.8.3 does not validate a client-supplied address value before using it as a storage key in one of its own options, allowing unauthenticated attackers to grow that option without bound and to slow the site's handling of missing pages.
EPSS
Процентиль: 16%
0.00248
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-400