Логотип exploitDog
bind:CVE-2021-39333
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-39333

Количество 2

Количество 2

nvd логотип

CVE-2021-39333

больше 4 лет назад

The Hashthemes Demo Importer Plugin <= 1.1.1 for WordPress contained several AJAX functions which relied on a nonce which was visible to all logged-in users for access control, allowing them to execute a function that truncated nearly all database tables and removed the contents of wp-content/uploads.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-6vp6-c735-397c

больше 3 лет назад

The Hashthemes Demo Importer Plugin <= 1.1.1 for WordPress contained several AJAX functions which relied on a nonce which was visible to all logged-in users for access control, allowing them to execute a function that truncated nearly all database tables and removed the contents of wp-content/uploads.

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-39333

The Hashthemes Demo Importer Plugin <= 1.1.1 for WordPress contained several AJAX functions which relied on a nonce which was visible to all logged-in users for access control, allowing them to execute a function that truncated nearly all database tables and removed the contents of wp-content/uploads.

CVSS3: 8.1
0%
Низкий
больше 4 лет назад
github логотип
GHSA-6vp6-c735-397c

The Hashthemes Demo Importer Plugin <= 1.1.1 for WordPress contained several AJAX functions which relied on a nonce which was visible to all logged-in users for access control, allowing them to execute a function that truncated nearly all database tables and removed the contents of wp-content/uploads.

CVSS3: 8.1
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу