Логотип exploitDog
bind:CVE-2021-24840
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-24840

Количество 2

Количество 2

nvd логотип

CVE-2021-24840

почти 4 года назад

The Squaretype WordPress theme before 3.0.4 allows unauthenticated users to manipulate the query_vars used to retrieve the posts to display in one of its REST endpoint, without any validation. As a result, private and scheduled posts could be retrieved via a crafted request.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-25vj-qm23-fx63

около 3 лет назад

The Squaretype WordPress theme before 3.0.4 allows unauthenticated users to manipulate the query_vars used to retrieve the posts to display in one of its REST endpoint, without any validation. As a result, private and scheduled posts could be retrieved via a crafted request.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-24840

The Squaretype WordPress theme before 3.0.4 allows unauthenticated users to manipulate the query_vars used to retrieve the posts to display in one of its REST endpoint, without any validation. As a result, private and scheduled posts could be retrieved via a crafted request.

CVSS3: 5.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-25vj-qm23-fx63

The Squaretype WordPress theme before 3.0.4 allows unauthenticated users to manipulate the query_vars used to retrieve the posts to display in one of its REST endpoint, without any validation. As a result, private and scheduled posts could be retrieved via a crafted request.

0%
Низкий
около 3 лет назад

Уязвимостей на страницу