CVE-2024-13182
WP Directorybox Manager <= 2.5 - Authentication Bypass
Vexday Risk Score
28Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 9.8EPSS 0.6%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
13 fev 2025Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
The WP Directorybox Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.5. This is due to incorrect authentication in the 'wp_dp_parse_request' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
Chimpstudio · WP Directorybox ManagerQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →