Логотип exploitDog
bind:CVE-2024-1870
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-1870

Количество 2

Количество 2

nvd логотип

CVE-2024-1870

почти 2 года назад

The Colibri Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the callActivateLicenseEndpoint function in all versions up to, and including, 1.0.260. This makes it possible for authenticated attackers, with subscriber access or higher, to update the license key.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-6pw4-99gp-9gj7

почти 2 года назад

The Colibri Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the callActivateLicenseEndpoint function in all versions up to, and including, 1.0.260. This makes it possible for authenticated attackers, with subscriber access or higher, to update the license key.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-1870

The Colibri Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the callActivateLicenseEndpoint function in all versions up to, and including, 1.0.260. This makes it possible for authenticated attackers, with subscriber access or higher, to update the license key.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-6pw4-99gp-9gj7

The Colibri Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the callActivateLicenseEndpoint function in all versions up to, and including, 1.0.260. This makes it possible for authenticated attackers, with subscriber access or higher, to update the license key.

CVSS3: 4.3
0%
Низкий
почти 2 года назад

Уязвимостей на страницу