Lucene search

K
wpvulndbWpvulndbWPVDB-ID:79C73A0A-087F-4971-A95F-C21D1D4DB26E
HistoryFeb 26, 2024 - 12:00 a.m.

Relevanssi < 4.22.1 - Unauthenticated Query Log Export

2024-02-2600:00:00
wpscan.com
5
relevanssi
vulnerability
unauthenticated access
data exposure
capability check
authorization control
software

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

7.1 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

21.4%

Description The plugin is vulnerable to unauthorized access of data due to a missing capability check on the relevanssi_export_log_check() function, allowing unauthenticated attackers to export the query log data. The vendor has indicated that they may look into adding a capability check for proper authorization control, however, this vulnerability is theoretically patched as is.

CPENameOperatorVersion
eq4.22.1

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

7.1 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

21.4%

Related for WPVDB-ID:79C73A0A-087F-4971-A95F-C21D1D4DB26E