6.5
CVE-2023-6139
- EPSS 0.61%
- Veröffentlicht 08.01.2024 19:15:09
- Zuletzt bearbeitet 03.06.2025 15:15:50
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Essential Real Estate < 4.4.0 - Subscriber+ Denial of Service via Arbitrary Option Update
Essential Real Estate <= 4.3.5 - Missing Authorization to Denial of Service
The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow attackers with a subscriber account to conduct Denial of Service attacks.
Mögliche Gegenmaßnahme
Essential Real Estate: Update to version 4.4.0, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
G5plus ≫ Essential Real Estate SwPlatformwordpress Version < 4.4.0
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Essential Real Estate
Version
*-4.3.5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.61% | 0.444 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
|
https://wpscan.com/vulnerability/96396a22-f523-4c51-8b72-52be266988aa
https://www.wordfence.com/threat-intel/vulnerabilities/id/74fa5a77-3c66-4aa5-aa58-3e608e3cba70