Логотип exploitDog
bind:CVE-2022-4972
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-4972

Количество 2

Количество 2

nvd логотип

CVE-2022-4972

больше 1 года назад

The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST-API routes related to reporting in versions up to, and including, 4.7.51. This makes it possible for unauthenticated attackers to view user data and other sensitive information intended for administrators.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-88wj-fxpv-pc7g

больше 1 года назад

The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST-API routes related to reporting in versions up to, and including, 4.7.51. This makes it possible for unauthenticated attackers to view user data and other sensitive information intended for administrators.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-4972

The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST-API routes related to reporting in versions up to, and including, 4.7.51. This makes it possible for unauthenticated attackers to view user data and other sensitive information intended for administrators.

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-88wj-fxpv-pc7g

The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST-API routes related to reporting in versions up to, and including, 4.7.51. This makes it possible for unauthenticated attackers to view user data and other sensitive information intended for administrators.

CVSS3: 7.5
1%
Низкий
больше 1 года назад

Уязвимостей на страницу