CVE-2021-4371
WP Quick FrontEnd Editor <= 5.5 - Authenticated Settings Change
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 4.3EPSS 0.7%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
07 jun 2023Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to Setting Changs in versions up to, and including, 5.5. This is due to lacking both a security nonce and a capabilities check. This makes it possible for low-authenticated attackers to change plugin settings even when they do not have the capabilities to do so.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Productos afectados
labibahmed42 · WP Quick FrontEnd Editor – WordPress Plugin¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →