Логотип exploitDog
bind:CVE-2025-10684
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-10684

Количество 2

Количество 2

nvd логотип

CVE-2025-10684

около 2 месяцев назад

The Construction Light WordPress theme before 1.6.8 does not have authorisation and CSRF when activating via an AJAX action, allowing any authenticated users, such as subscriber to activate arbitrary .

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-9887-33qw-3wcg

около 2 месяцев назад

The Construction Light WordPress theme before 1.6.8 does not have authorisation and CSRF when activating via an AJAX action, allowing any authenticated users, such as subscriber to activate arbitrary .

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-10684

The Construction Light WordPress theme before 1.6.8 does not have authorisation and CSRF when activating via an AJAX action, allowing any authenticated users, such as subscriber to activate arbitrary .

CVSS3: 4.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-9887-33qw-3wcg

The Construction Light WordPress theme before 1.6.8 does not have authorisation and CSRF when activating via an AJAX action, allowing any authenticated users, such as subscriber to activate arbitrary .

CVSS3: 4.3
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу