Логотип exploitDog
bind:CVE-2025-11127
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-11127

Количество 2

Количество 2

nvd логотип

CVE-2025-11127

3 месяца назад

The Mstoreapp Mobile App WordPress plugin through 2.08 and Mstoreapp Mobile Multivendor through 9.0.1 do not properly verify users identify when using an AJAX action, allowing unauthenticated users to retrieve a valid session for arbitrary users by knowing their email address.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-9mf8-fwp6-wv6x

3 месяца назад

The Mstoreapp Mobile App WordPress plugin through 2.08 and Mstoreapp Mobile Multivendor through 9.0.1 do not properly verify users identify when using an AJAX action, allowing unauthenticated users to retrieve a valid session for arbitrary users by knowing their email address.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-11127

The Mstoreapp Mobile App WordPress plugin through 2.08 and Mstoreapp Mobile Multivendor through 9.0.1 do not properly verify users identify when using an AJAX action, allowing unauthenticated users to retrieve a valid session for arbitrary users by knowing their email address.

CVSS3: 9.8
0%
Низкий
3 месяца назад
github логотип
GHSA-9mf8-fwp6-wv6x

The Mstoreapp Mobile App WordPress plugin through 2.08 and Mstoreapp Mobile Multivendor through 9.0.1 do not properly verify users identify when using an AJAX action, allowing unauthenticated users to retrieve a valid session for arbitrary users by knowing their email address.

CVSS3: 9.8
0%
Низкий
3 месяца назад

Уязвимостей на страницу