Логотип exploitDog
bind:CVE-2023-0772
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-0772

Количество 2

Количество 2

nvd логотип

CVE-2023-0772

почти 3 года назад

The Popup Builder by OptinMonster WordPress plugin before 2.12.2 does not ensure that the campaign to be loaded via some shortcodes is actually a campaign, allowing any authenticated users such as subscriber to retrieve the content of arbitrary posts, like draft, private or even password protected ones.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-w5vw-x33c-r8g6

почти 3 года назад

The Popup Builder by OptinMonster WordPress plugin before 2.12.2 does not ensure that the campaign to be loaded via some shortcodes is actually a campaign, allowing any authenticated users such as subscriber to retrieve the content of arbitrary posts, like draft, private or even password protected ones.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-0772

The Popup Builder by OptinMonster WordPress plugin before 2.12.2 does not ensure that the campaign to be loaded via some shortcodes is actually a campaign, allowing any authenticated users such as subscriber to retrieve the content of arbitrary posts, like draft, private or even password protected ones.

CVSS3: 6.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-w5vw-x33c-r8g6

The Popup Builder by OptinMonster WordPress plugin before 2.12.2 does not ensure that the campaign to be loaded via some shortcodes is actually a campaign, allowing any authenticated users such as subscriber to retrieve the content of arbitrary posts, like draft, private or even password protected ones.

CVSS3: 6.5
0%
Низкий
почти 3 года назад

Уязвимостей на страницу