← voltar
CVE-2024-11349criticalexploração observadaCWE-288

AdForest <= 5.1.6 - Authentication Bypass

50Vexday Risk Score

Priorize a correção. Ela exploração observada pelo VulnCheck.

ssvc Actcvss 9.8epss 1.2%
da publicação à arma
Publicada no NVD21 de dez.
VulnCheck+500d
probabilidade de exploração
1.2%top 34% das CVEs
exploração observada
simVulnCheck
The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.6. This is due to the plugin not properly verifying a user's identity prior to authenticating them through the sb_login_user_with_otp_fun() function. This makes it possible for unauthenticated attackers to log in as arbitrary users, including administrators.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
scriptsbundle · AdForest