Логотип exploitDog
bind:CVE-2023-6008
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-6008

Количество 2

Количество 2

nvd логотип

CVE-2023-6008

около 2 лет назад

The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.1. This is due to missing or incorrect nonce validation on multiple functions. This makes it possible for unauthenticated attackers to add, modify, or delete user meta and plugin options.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-9jqw-c7jc-7p6v

около 2 лет назад

The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.1. This is due to missing or incorrect nonce validation on multiple functions. This makes it possible for unauthenticated attackers to add, modify, or delete user meta and plugin options.

CVSS3: 6.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-6008

The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.1. This is due to missing or incorrect nonce validation on multiple functions. This makes it possible for unauthenticated attackers to add, modify, or delete user meta and plugin options.

CVSS3: 6.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-9jqw-c7jc-7p6v

The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.1. This is due to missing or incorrect nonce validation on multiple functions. This makes it possible for unauthenticated attackers to add, modify, or delete user meta and plugin options.

CVSS3: 6.3
0%
Низкий
около 2 лет назад

Уязвимостей на страницу