Логотип exploitDog
bind:CVE-2025-13307
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-13307

Количество 2

Количество 2

nvd логотип

CVE-2025-13307

около 2 месяцев назад

The Ocean Modal Window WordPress plugin before 2.3.3 is vulnerable to Remote Code Execution via the modal display logic. These modals can be displayed under user-controlled conditions that Editors and Administrators can set (edit_pages capability). The conditions are then executed as part of an eval statement executed on every site page. This leads to remote code execution.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-7vhr-jxp7-33h3

около 2 месяцев назад

The Ocean Modal Window WordPress plugin before 2.3.3 is vulnerable to Remote Code Execution via the modal display logic. These modals can be displayed under user-controlled conditions that Editors and Administrators can set (edit_pages capability). The conditions are then executed as part of an eval statement executed on every site page. This leads to remote code execution.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-13307

The Ocean Modal Window WordPress plugin before 2.3.3 is vulnerable to Remote Code Execution via the modal display logic. These modals can be displayed under user-controlled conditions that Editors and Administrators can set (edit_pages capability). The conditions are then executed as part of an eval statement executed on every site page. This leads to remote code execution.

CVSS3: 7.2
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-7vhr-jxp7-33h3

The Ocean Modal Window WordPress plugin before 2.3.3 is vulnerable to Remote Code Execution via the modal display logic. These modals can be displayed under user-controlled conditions that Editors and Administrators can set (edit_pages capability). The conditions are then executed as part of an eval statement executed on every site page. This leads to remote code execution.

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу