Логотип exploitDog
bind:CVE-2023-3999
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-3999

Количество 2

Количество 2

nvd логотип

CVE-2023-3999

больше 2 лет назад

The Waiting: One-click countdowns plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on its AJAX calls in versions up to, and including, 0.6.2. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to create and delete countdowns as well as manipulate other plugin settings.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3744-v8vp-h2jq

больше 2 лет назад

The Waiting: One-click countdowns plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on its AJAX calls in versions up to, and including, 0.6.2. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to create and delete countdowns as well as manipulate other plugin settings.

CVSS3: 6.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-3999

The Waiting: One-click countdowns plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on its AJAX calls in versions up to, and including, 0.6.2. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to create and delete countdowns as well as manipulate other plugin settings.

CVSS3: 6.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3744-v8vp-h2jq

The Waiting: One-click countdowns plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on its AJAX calls in versions up to, and including, 0.6.2. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to create and delete countdowns as well as manipulate other plugin settings.

CVSS3: 6.3
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу