Логотип exploitDog
bind:CVE-2023-6295
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-6295

Количество 2

Количество 2

nvd логотип

CVE-2023-6295

около 2 лет назад

The SiteOrigin Widgets Bundle WordPress plugin before 1.51.0 does not validate user input before using it to generate paths passed to include function/s, allowing users with the administrator role to perform LFI attacks in the context of Multisite WordPress sites.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-gwvq-pm88-g84j

около 2 лет назад

The SiteOrigin Widgets Bundle WordPress plugin before 1.51.0 does not validate user input before using it to generate paths passed to include function/s, allowing users with the administrator role to perform LFI attacks in the context of Multisite WordPress sites.

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-6295

The SiteOrigin Widgets Bundle WordPress plugin before 1.51.0 does not validate user input before using it to generate paths passed to include function/s, allowing users with the administrator role to perform LFI attacks in the context of Multisite WordPress sites.

CVSS3: 7.2
0%
Низкий
около 2 лет назад
github логотип
GHSA-gwvq-pm88-g84j

The SiteOrigin Widgets Bundle WordPress plugin before 1.51.0 does not validate user input before using it to generate paths passed to include function/s, allowing users with the administrator role to perform LFI attacks in the context of Multisite WordPress sites.

CVSS3: 7.2
0%
Низкий
около 2 лет назад

Уязвимостей на страницу