← volver
CVE-2021-4374criticalexplotación observadaCWE-862

WordPress Automatic Plugin <= 3.53.2 - Unauthenticated Arbitrary Options Update

70Vexday Risk Score

Corrige ahora. Ella explotación observada por VulnCheck y tiene exploit funcional público.

ssvc Actcvss 9.1epss 16%
de la publicación al arma0 días
Publicada en NVD7 jun
metasploit6 sept
VulnCheck6 sept
probabilidad de explotación
16%top 3% de las CVE
explotación observada
VulnCheck
The WordPress Automatic Plugin for WordPress is vulnerable to arbitrary options updates in versions up to, and including, 3.53.2. This is due to missing authorization and option validation in the process_form.php file. This makes it possible for unauthenticated attackers to arbitrarily update the settings of a vulnerable site and ultimately compromise the entire site.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H