6.5
CVE-2022-4384
- EPSS 0.61%
- Veröffentlicht 06.02.2023 20:15:11
- Zuletzt bearbeitet 25.03.2025 21:15:38
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Stream <= 3.9.1 - Missing Authorization to Sensitive Information Disclosure
The Stream WordPress plugin before 3.9.2 does not prevent users with little privileges on the site (like subscribers) from using its alert creation functionality, which may enable them to leak sensitive information.
Mögliche Gegenmaßnahme
Stream: Update to version 3.9.2, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Stream
Version
* - 3.9.1
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.61% | 0.689 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|