Логотип exploitDog
bind:CVE-2021-24192
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-24192

Количество 3

Количество 3

nvd логотип

CVE-2021-24192

больше 4 лет назад

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Tree Sitemap WordPress plugin before 2.9, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-qvhh-p8m2-pw7f

больше 3 лет назад

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Tree Sitemap WordPress plugin before 2.9, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

CVSS3: 8.8
EPSS: Низкий
fstec логотип

BDU:2021-03307

больше 4 лет назад

Уязвимость функции cp_plugins_do_button_job_later_callback плагина Tree Sitemap WordPress, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-24192

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Tree Sitemap WordPress plugin before 2.9, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-qvhh-p8m2-pw7f

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Tree Sitemap WordPress plugin before 2.9, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
fstec логотип
BDU:2021-03307

Уязвимость функции cp_plugins_do_button_job_later_callback плагина Tree Sitemap WordPress, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу