5.3
CVE-2024-6499
- EPSS 0.46%
- Veröffentlicht 24.08.2024 04:15:07
- Zuletzt bearbeitet 26.09.2024 22:07:50
- Quelle security@wordfence.com
- CVE-Watchlists
- Unerledigt
WordPress Button Plugin MaxButtons <= 9.7.8 - Full Path Disclosure
The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 9.7.8. This makes it possible for unauthenticated attackers to obtain the full path to instances, which they may be able to use in combination with other vulnerabilities or to simplify reconnaissance work. On its own, this information is of very limited use.
Mögliche Gegenmaßnahme
MaxButtons – Create buttons: Update to version 9.8.0, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
MaxButtons – Create buttons
Version
*-9.7.8
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Maxfoundry ≫ Maxbuttons SwPlatformwordpress Version < 9.8.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.46% | 0.636 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@wordfence.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.