Логотип exploitDog
bind:CVE-2024-8853
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-8853

Количество 2

Количество 2

nvd логотип

CVE-2024-8853

больше 1 года назад

The Webo-facto plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.40 due to insufficient restriction on the 'doSsoAuthentification' function. This makes it possible for unauthenticated attackers to make themselves administrators by registering with a username that contains '-wfuser'.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-rfjc-67p6-84v6

больше 1 года назад

The Webo-facto plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.40 due to insufficient restriction on the 'doSsoAuthentification' function. This makes it possible for unauthenticated attackers to make themselves administrators by registering with a username that contains '-wfuser'.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-8853

The Webo-facto plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.40 due to insufficient restriction on the 'doSsoAuthentification' function. This makes it possible for unauthenticated attackers to make themselves administrators by registering with a username that contains '-wfuser'.

CVSS3: 9.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-rfjc-67p6-84v6

The Webo-facto plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.40 due to insufficient restriction on the 'doSsoAuthentification' function. This makes it possible for unauthenticated attackers to make themselves administrators by registering with a username that contains '-wfuser'.

CVSS3: 9.8
0%
Низкий
больше 1 года назад

Уязвимостей на страницу