Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-21739
HistoryDec 28, 2021 - 12:00 a.m.

WordPress WP Guppy Plugin Information Disclosure Vulnerability

2021-12-2800:00:00
China National Vulnerability Database
www.cnvd.org.cn
7

0.002 Low

EPSS

Percentile

56.5%

WordPress is the Wordpress Foundation’s suite of blogging platforms developed using the PHP language. The platform supports the hosting of personal blog sites on servers with PHP and MySQL. WordPress WP Guppy Plugin prior to version 1.3 is vulnerable to an information disclosure vulnerability that stems from the plugin not authorizing any user to call them in certain REST API endpoints. An attacker could exploit this vulnerability to cause sensitive information to be compromised.

CPENameOperatorVersion
wordpress wp guppy pluginlt1.3

0.002 Low

EPSS

Percentile

56.5%