Логотип exploitDog
bind:CVE-2025-13820
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-13820

Количество 2

Количество 2

nvd логотип

CVE-2025-13820

около 1 месяца назад

The Comments WordPress plugin before 7.6.40 does not properly validate user's identity when using the disqus.com provider, allowing an attacker to log in to any user (when knowing their email address) when such user does not have an account on disqus.com yet.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-77g2-3gj2-8h4q

около 1 месяца назад

The Comments WordPress plugin before 7.6.40 does not properly validate user's identity when using the disqus.com provider, allowing an attacker to log in to any user (when knowing their email address) when such user does not have an account on disqus.com yet.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-13820

The Comments WordPress plugin before 7.6.40 does not properly validate user's identity when using the disqus.com provider, allowing an attacker to log in to any user (when knowing their email address) when such user does not have an account on disqus.com yet.

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-77g2-3gj2-8h4q

The Comments WordPress plugin before 7.6.40 does not properly validate user's identity when using the disqus.com provider, allowing an attacker to log in to any user (when knowing their email address) when such user does not have an account on disqus.com yet.

CVSS3: 5.3
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу