Логотип exploitDog
bind:CVE-2025-3102
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-3102

Количество 3

Количество 3

nvd логотип

CVE-2025-3102

10 месяцев назад

The SureTriggers: All-in-One Automation Platform plugin for WordPress is vulnerable to an authentication bypass leading to administrative account creation due to a missing empty value check on the 'secret_key' value in the 'autheticate_user' function in all versions up to, and including, 1.0.78. This makes it possible for unauthenticated attackers to create administrator accounts on the target website when the plugin is installed and activated but not configured with an API key.

CVSS3: 8.1
EPSS: Высокий
github логотип

GHSA-rp6h-6758-g8ch

10 месяцев назад

The SureTriggers: All-in-One Automation Platform plugin for WordPress is vulnerable to an authentication bypass leading to administrative account creation due to a missing empty value check on the 'secret_key' value in the 'autheticate_user' function in all versions up to, and including, 1.0.78. This makes it possible for unauthenticated attackers to create administrator accounts on the target website when the plugin is installed and activated but not configured with an API key.

CVSS3: 8.1
EPSS: Высокий
fstec логотип

BDU:2025-04970

10 месяцев назад

Уязвимость плагина SureTriggers системы управления содержимым сайта WordPress, позволяющая нарушителю создавать учетные записи администраторов на сайте

CVSS3: 8.1
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-3102

The SureTriggers: All-in-One Automation Platform plugin for WordPress is vulnerable to an authentication bypass leading to administrative account creation due to a missing empty value check on the 'secret_key' value in the 'autheticate_user' function in all versions up to, and including, 1.0.78. This makes it possible for unauthenticated attackers to create administrator accounts on the target website when the plugin is installed and activated but not configured with an API key.

CVSS3: 8.1
87%
Высокий
10 месяцев назад
github логотип
GHSA-rp6h-6758-g8ch

The SureTriggers: All-in-One Automation Platform plugin for WordPress is vulnerable to an authentication bypass leading to administrative account creation due to a missing empty value check on the 'secret_key' value in the 'autheticate_user' function in all versions up to, and including, 1.0.78. This makes it possible for unauthenticated attackers to create administrator accounts on the target website when the plugin is installed and activated but not configured with an API key.

CVSS3: 8.1
87%
Высокий
10 месяцев назад
fstec логотип
BDU:2025-04970

Уязвимость плагина SureTriggers системы управления содержимым сайта WordPress, позволяющая нарушителю создавать учетные записи администраторов на сайте

CVSS3: 8.1
87%
Высокий
10 месяцев назад

Уязвимостей на страницу