Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 3

Количество 3

nvd логотип

CVE-2025-3102

больше 1 года назад

The SureTriggers: All-in-One Automation Platform plugin for WordPress is vulnerable to an authentication bypass leading to administrative account creation due to a missing empty value check on the 'secret_key' value in the 'autheticate_user' function in all versions up to, and including, 1.0.78. This makes it possible for unauthenticated attackers to create administrator accounts on the target website when the plugin is installed and activated but not configured with an API key.

CVSS3: 8.1
EPSS: Высокий
github логотип

GHSA-rp6h-6758-g8ch

больше 1 года назад

The SureTriggers: All-in-One Automation Platform plugin for WordPress is vulnerable to an authentication bypass leading to administrative account creation due to a missing empty value check on the 'secret_key' value in the 'autheticate_user' function in all versions up to, and including, 1.0.78. This makes it possible for unauthenticated attackers to create administrator accounts on the target website when the plugin is installed and activated but not configured with an API key.

CVSS3: 8.1
EPSS: Высокий
fstec логотип

BDU:2025-04970

больше 1 года назад

Уязвимость плагина SureTriggers системы управления содержимым сайта WordPress, позволяющая нарушителю создавать учетные записи администраторов на сайте

CVSS3: 8.1
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-3102

The SureTriggers: All-in-One Automation Platform plugin for WordPress is vulnerable to an authentication bypass leading to administrative account creation due to a missing empty value check on the 'secret_key' value in the 'autheticate_user' function in all versions up to, and including, 1.0.78. This makes it possible for unauthenticated attackers to create administrator accounts on the target website when the plugin is installed and activated but not configured with an API key.

CVSS3: 8.1
76%
Высокий
больше 1 года назад
github логотип
GHSA-rp6h-6758-g8ch

The SureTriggers: All-in-One Automation Platform plugin for WordPress is vulnerable to an authentication bypass leading to administrative account creation due to a missing empty value check on the 'secret_key' value in the 'autheticate_user' function in all versions up to, and including, 1.0.78. This makes it possible for unauthenticated attackers to create administrator accounts on the target website when the plugin is installed and activated but not configured with an API key.

CVSS3: 8.1
76%
Высокий
больше 1 года назад
fstec логотип
BDU:2025-04970

Уязвимость плагина SureTriggers системы управления содержимым сайта WordPress, позволяющая нарушителю создавать учетные записи администраторов на сайте

CVSS3: 8.1
76%
Высокий
больше 1 года назад

Уязвимостей на страницу