Логотип exploitDog
bind:CVE-2022-3394
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-3394

Количество 2

Количество 2

nvd логотип

CVE-2022-3394

больше 3 лет назад

The WP All Export Pro WordPress plugin before 1.7.9 does not limit some functionality during exports only to users with the Administrator role, allowing any logged in user which has been given privileges to perform exports to execute arbitrary code on the site. By default only administrators can run exports, but the privilege can be delegated to lower privileged users.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-vh4p-xvjw-q6rc

больше 3 лет назад

The WP All Export Pro WordPress plugin before 1.7.9 does not limit some functionality during exports only to users with the Administrator role, allowing any logged in user which has been given privileges to perform exports to execute arbitrary code on the site. By default only administrators can run exports, but the privilege can be delegated to lower privileged users.

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-3394

The WP All Export Pro WordPress plugin before 1.7.9 does not limit some functionality during exports only to users with the Administrator role, allowing any logged in user which has been given privileges to perform exports to execute arbitrary code on the site. By default only administrators can run exports, but the privilege can be delegated to lower privileged users.

CVSS3: 7.2
1%
Низкий
больше 3 лет назад
github логотип
GHSA-vh4p-xvjw-q6rc

The WP All Export Pro WordPress plugin before 1.7.9 does not limit some functionality during exports only to users with the Administrator role, allowing any logged in user which has been given privileges to perform exports to execute arbitrary code on the site. By default only administrators can run exports, but the privilege can be delegated to lower privileged users.

CVSS3: 7.2
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу