7.2

CVE-2022-42459

WordPress Image Hover Effects Ultimate plugin <= 9.7.1 - Auth. WordPress Options Change vulnerability

Image Hover Effects Ultimate <= 9.7.1 - Authenticated (Admin+) Arbitrary Options Update

Auth. WordPress Options Change vulnerability in Image Hover Effects Ultimate plugin <= 9.7.1 on WordPress.
Mögliche Gegenmaßnahme
Image Hover Effects Ultimate ( Image Gallery, Effects, Lightbox, Comparison & Magnifier ): Update to version 9.7.2, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OxilabImage Hover Effects Ultimate SwPlatformwordpress Version <= 9.7.1
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Image Hover Effects Ultimate ( Image Gallery, Effects, Lightbox, Comparison & Magnifier )
Version *-9.7.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.8% 0.517
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
audit@patchstack.com 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

https://patchstack.com/database/vulnerability/image-hover-effects-ultimate/wordpress-image-hover-effects-ultimate-plugin-9-7-1-auth-wordpress-options-change-vulnerability?_s_id=cve
Third Party Advisory
https://wordpress.org/plugins/image-hover-effects-ultimate/
Third Party Advisory
Product
https://www.wordfence.com/threat-intel/vulnerabilities/id/15c2cc20-8d10-4e77-8009-df91e171183f
Third Party Advisory