Lucene search

K
cvePatchstackCVE-2024-27953
HistoryMar 13, 2024 - 5:15 p.m.

CVE-2024-27953

2024-03-1317:15:48
CWE-862
Patchstack
web.nvd.nist.gov
17
cve-2024-27953
missing authorization
cryptocurrency widgets
price ticker
coins list
vulnerability
nvd

CVSS3

4.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

AI Score

5.8

Confidence

High

EPSS

0

Percentile

9.0%

Missing Authorization vulnerability in Cool Plugins Cryptocurrency Widgets – Price Ticker & Coins List.This issue affects Cryptocurrency Widgets – Price Ticker & Coins List: from n/a through 2.6.8.

Affected configurations

Vulners
Node
cool_pluginscryptocurrency_widgets_–_price_ticker_\&_coins_listRange2.6.8wordpress
VendorProductVersionCPE
cool_pluginscryptocurrency_widgets_–_price_ticker_\&_coins_list*cpe:2.3:a:cool_plugins:cryptocurrency_widgets_–_price_ticker_\&_coins_list:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "collectionURL": "https://wordpress.org/plugins",
    "defaultStatus": "unaffected",
    "packageName": "cryptocurrency-price-ticker-widget",
    "product": "Cryptocurrency Widgets – Price Ticker & Coins List",
    "vendor": "Cool Plugins",
    "versions": [
      {
        "changes": [
          {
            "at": "2.6.9",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "2.6.8",
        "status": "affected",
        "version": "n/a",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

4.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

AI Score

5.8

Confidence

High

EPSS

0

Percentile

9.0%