CVE-2024-9931
CVE-2024-9931
Título es
CVE-2024-9931
Sáb, 26/10/2024 – 03:15
Tipo
CWE-288
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2024-9931
Descripción en
The Wux Blog Editor plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.0.0. This is due to missing validation on the token being supplied during the autologin through the plugin. This makes it possible for unauthenticated attackers to log in to the first administrator user.
26/10/2024
26/10/2024
Vector CVSS:3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Gravedad 3.1 (CVSS 3.1 Base Score)
9.80
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
CRITICAL
Referencias
Enviar en el boletín
Off
