Логотип exploitDog
bind:CVE-2025-0764
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-0764

Количество 2

Количество 2

nvd логотип

CVE-2025-0764

12 месяцев назад

The wpForo Forum plugin for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'update' method of the 'Members' class in all versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with subscriber-level privileges or higher, to read arbitrary files on the server.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-9wh9-687v-6mqp

12 месяцев назад

The wpForo Forum plugin for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'update' method of the 'Members' class in all versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with subscriber-level privileges or higher, to read arbitrary files on the server.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-0764

The wpForo Forum plugin for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'update' method of the 'Members' class in all versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with subscriber-level privileges or higher, to read arbitrary files on the server.

CVSS3: 6.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-9wh9-687v-6mqp

The wpForo Forum plugin for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'update' method of the 'Members' class in all versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with subscriber-level privileges or higher, to read arbitrary files on the server.

CVSS3: 6.5
0%
Низкий
12 месяцев назад

Уязвимостей на страницу