Логотип exploitDog
bind:CVE-2021-24997
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-24997

Количество 2

Количество 2

nvd логотип

CVE-2021-24997

около 4 лет назад

The WP Guppy WordPress plugin before 1.3 does not have any authorisation in some of the REST API endpoints, allowing any user to call them and could lead to sensitive information disclosure, such as usernames and chats between users, as well as be able to send messages as an arbitrary user

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-f373-v3ww-mcwj

около 4 лет назад

The WP Guppy WordPress plugin before 1.3 does not have any authorisation in some of the REST API endpoints, allowing any user to call them and could lead to sensitive information disclosure, such as usernames and chats between users, as well as be able to send messages as an arbitrary user

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-24997

The WP Guppy WordPress plugin before 1.3 does not have any authorisation in some of the REST API endpoints, allowing any user to call them and could lead to sensitive information disclosure, such as usernames and chats between users, as well as be able to send messages as an arbitrary user

CVSS3: 6.5
5%
Низкий
около 4 лет назад
github логотип
GHSA-f373-v3ww-mcwj

The WP Guppy WordPress plugin before 1.3 does not have any authorisation in some of the REST API endpoints, allowing any user to call them and could lead to sensitive information disclosure, such as usernames and chats between users, as well as be able to send messages as an arbitrary user

5%
Низкий
около 4 лет назад

Уязвимостей на страницу