6.5
CVE-2023-6139
- EPSS 0.22%
- Veröffentlicht 08.01.2024 19:15:09
- Zuletzt bearbeitet 03.06.2025 15:15:50
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Essential Real Estate <= 4.3.5 - Missing Authorization to Denial of Service
The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow attackers with a subscriber account to conduct Denial of Service attacks.
Mögliche Gegenmaßnahme
Essential Real Estate: Update to version 4.4.0, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Essential Real Estate
Version
*-4.3.5
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
G5plus ≫ Essential Real Estate SwPlatformwordpress Version < 4.4.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.445 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
|