Логотип exploitDog
bind:CVE-2025-0180
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-0180

Количество 2

Количество 2

nvd логотип

CVE-2025-0180

12 месяцев назад

The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3. This is due to the plugin not properly restricting what user meta can be updated during profile registration. This makes it possible for unauthenticated attackers to register on the site as an administrator.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-q5xq-vwc2-mfrm

12 месяцев назад

The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3. This is due to the plugin not properly restricting what user meta can be updated during profile registration. This makes it possible for unauthenticated attackers to register on the site as an administrator.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-0180

The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3. This is due to the plugin not properly restricting what user meta can be updated during profile registration. This makes it possible for unauthenticated attackers to register on the site as an administrator.

CVSS3: 9.8
1%
Низкий
12 месяцев назад
github логотип
GHSA-q5xq-vwc2-mfrm

The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3. This is due to the plugin not properly restricting what user meta can be updated during profile registration. This makes it possible for unauthenticated attackers to register on the site as an administrator.

CVSS3: 9.8
1%
Низкий
12 месяцев назад

Уязвимостей на страницу