6.5
CVE-2022-4239
- EPSS 0.12%
- Veröffentlicht 26.12.2022 13:15:13
- Zuletzt bearbeitet 14.04.2025 14:15:23
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Workreap <= 2.6.3 - Insecure Direct Object Reference
The Workreap WordPress theme before 2.6.4 does not verify that an addon service belongs to the user issuing the request, or indeed that it is an addon service, when processing the workreap_addons_service_remove action, allowing any user to delete any post by knowing or guessing the id.
Mögliche Gegenmaßnahme
Workreap - Freelance Marketplace and Directory WordPress Theme: Update to version 2.6.4, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Theme
≫
Produkt
Workreap - Freelance Marketplace and Directory WordPress Theme
Version
* - 2.6.3
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Amentotech ≫ Workreap SwPlatformwordpress Version < 2.6.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.12% | 0.309 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
|