4.3

CVE-2023-6289

Exploit

Swift Performance Lite <= 2.3.6.14 - Unauthenticated Configuration Export

Swift Performance Lite <= 2.3.6.14 - Missing Authorization to Unauthenticated Settings Export

The Swift Performance Lite WordPress plugin before 2.3.6.15 does not prevent users from exporting the plugin's settings, which may include sensitive information such as Cloudflare API tokens.
Mögliche Gegenmaßnahme
Swift Performance Lite: Update to version 2.3.6.15, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SwtepluginsSwift Performance SwEditionlite SwPlatformwordpress Version < 2.3.6.15
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Swift Performance Lite
Version *-2.3.6.14
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.92% 0.555
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://wpscan.com/vulnerability/8c83dd57-9291-4dfc-846d-5ad47534e2ad
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/8321f68f-da2d-4382-979d-54008de2cae7
Third Party Advisory