Beveiligingsadvies

CVE-2023-0551

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2023-08-16 11:03:30
Laatst bijgewerkt 2024-10-08 19:13:55
Toegewezen door WPScan
CVSS-score geen score
Status PUBLISHED

Beschrijving

The REST API TO MiniProgram WordPress plugin through 4.6.1 does not have authorisation and CSRF checks in an AJAX action, allowing ay authenticated users, such as subscriber to call and delete arbitrary attachments