← voltar
CVE-2021-4374criticalexploração observadaCWE-862

WordPress Automatic Plugin <= 3.53.2 - Unauthenticated Arbitrary Options Update

70Vexday Risk Score

Corrija agora. Ela exploração observada pelo VulnCheck e tem exploit funcional público.

ssvc Actcvss 9.1epss 16%
da publicação à arma0 dias
Publicada no NVD7 de jun.
metasploit6 de set.
VulnCheck6 de set.
probabilidade de exploração
16%top 3% das CVEs
exploração observada
simVulnCheck
The WordPress Automatic Plugin for WordPress is vulnerable to arbitrary options updates in versions up to, and including, 3.53.2. This is due to missing authorization and option validation in the process_form.php file. This makes it possible for unauthenticated attackers to arbitrarily update the settings of a vulnerable site and ultimately compromise the entire site.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H