5.3
CVE-2025-11171
- EPSS 0.34%
- Veröffentlicht 08.10.2025 05:24:49
- Zuletzt bearbeitet 08.10.2025 19:38:09
- Quelle security@wordfence.com
- CVE-Watchlists
- Unerledigt
Chartify – WordPress Chart Plugin <= 3.5.9 - Missing Authentication for Administrative Function
The Chartify – WordPress Chart Plugin for WordPress is vulnerable to Missing Authentication for Critical Function in all versions up to, and including, 3.5.9. This is due to the plugin registering an unauthenticated AJAX action that dispatches to admin-class methods based on a request parameter, without any nonce or capability checks. This makes it possible for unauthenticated attackers to execute administrative functions via the wp-admin/admin-ajax.php endpoint granted they can identify callable method names.
Mögliche Gegenmaßnahme
Chartify – WordPress Chart Plugin: Update to version 3.6.0, or a newer patched version
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Chartify – WordPress Chart Plugin
Version
*-3.5.9
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerays-pro
≫
Produkt
Chartify – WordPress Chart Plugin
Default Statusunaffected
Version <=
3.5.9
Version
*
Status
affected
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.34% | 0.564 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@wordfence.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
|
CWE-306 Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.