4.3
CVE-2024-5331
- EPSS 0.15%
- Veröffentlicht 01.08.2024 07:15:02
- Zuletzt bearbeitet 21.11.2024 23:07:26
- Quelle security@wordfence.com
- CVE-Watchlists
- Unerledigt
Breakdance <= 1.7.2 - Missing Authorization
The Breakdance plugin for WordPress is vulnerable to unauthorized access of data in all versions up to, and including, 1.7.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to export form submissions.
Mögliche Gegenmaßnahme
Breakdance: Update to version 2.0.0, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Breakdance
Version
*-1.7.1
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Soflyy ≫ Breakdance SwPlatformwordpress Version < 2.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.15% | 0.356 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
| security@wordfence.com | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.