Логотип exploitDog
bind:CVE-2021-4383
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-4383

Количество 2

Количество 2

nvd логотип

CVE-2021-4383

больше 2 лет назад

The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to page content injection in versions up to, and including, 5.5. This is due to missing capability checks in the plugin's page-editing functionality. This makes it possible for low-authenticated attackers, such as subscribers, to edit/create any page or post on the blog.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-4xv7-93mm-vwcp

больше 2 лет назад

The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to page content injection in versions up to, and including, 5.5. This is due to missing capability checks in the plugin's page-editing functionality. This makes it possible for low-authenticated attackers, such as subscribers, to edit/create any page or post on the blog.

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-4383

The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to page content injection in versions up to, and including, 5.5. This is due to missing capability checks in the plugin's page-editing functionality. This makes it possible for low-authenticated attackers, such as subscribers, to edit/create any page or post on the blog.

CVSS3: 8.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4xv7-93mm-vwcp

The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to page content injection in versions up to, and including, 5.5. This is due to missing capability checks in the plugin's page-editing functionality. This makes it possible for low-authenticated attackers, such as subscribers, to edit/create any page or post on the blog.

CVSS3: 8.1
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу