← volver
CVE-2023-6600highexplotación observadaCWE-79CWE-862

OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. <= 5.7.9 - Missing Authorization to Unauthenticated Directory Deletion and Cross-Site Scripting

43Vexday Risk Score

Prioriza la corrección. Ella explotación observada por VulnCheck.

ssvc Actcvss 8.6epss 0.5%
de la publicación al arma
Publicada en NVD3 ene
VulnCheck2 ene
probabilidad de explotación
0.5%top 61% de las CVE
explotación observada
síVulnCheck
The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. plugin for WordPress is vulnerable to unauthorized modification of data and Stored Cross-Site Scripting due to a missing capability check on the update_settings() function hooked via admin_init in all versions up to, and including, 5.7.9. This makes it possible for unauthenticated attackers to update the plugin's settings which can be used to inject Cross-Site Scripting payloads and delete entire directories. PLease note there were several attempted patched, and we consider 5.7.10 to be the most sufficiently patched.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H