7.3
CVE-2020-36716
- EPSS 0.09%
- Veröffentlicht 07.06.2023 02:15:11
- Zuletzt bearbeitet 21.11.2024 05:30:08
- Quelle security@wordfence.com
- CVE-Watchlists
- Unerledigt
WP Activity Log <= 4.0.1 - Missing Authorization
The WP Activity Log plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the setup_page function in versions up to, and including, 4.0.1. This makes it possible for unauthenticated attackers to run the setup wizard (if it has not been run previously) and access plugin configuration options.
Mögliche Gegenmaßnahme
WP Activity Log: Update to version 4.0.2, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
WP Activity Log
Version
[*, 4.0.2)
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wpwhitesecurity ≫ Wp Activity Log SwPlatformwordpress Version <= 4.0.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.09% | 0.267 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.3 | 3.9 | 3.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
|
| security@wordfence.com | 7.3 | 3.9 | 3.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.