4.3
CVE-2023-4269
- EPSS 0.11%
- Veröffentlicht 04.09.2023 12:15:10
- Zuletzt bearbeitet 23.04.2025 17:16:42
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
User Activity Log <= 1.6.5 - Unauthenticated Data Export to Sensitive Information Disclosure
The User Activity Log WordPress plugin before 1.6.6 lacks proper authorisation when exporting its activity logs, allowing any authenticated users, such as subscriber to perform such action and retrieve PII such as email addresses.
Mögliche Gegenmaßnahme
User Activity Log: Update to version 1.6.6, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
User Activity Log
Version
*-1.6.5
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Solwininfotech ≫ User Activity Log SwPlatformwordpress Version < 1.6.6
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.11% | 0.303 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.