Lucene search

K
wpvulndbWpvulndbWPVDB-ID:9965AA9E-359E-4D9F-86C4-1CAEA1594799
HistoryDec 08, 2023 - 12:00 a.m.

System Dashboard < 2.8.8 - Missing Authorization to Information Disclosure (sd_global_value)

2023-12-0800:00:00
wpscan.com
4
wordpress
dashboard plugin
unauthorized access

6.4 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

20.5%

Description The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_global_value() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve sensitive global value information.

CPENameOperatorVersion
eq2.8.8

6.4 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

20.5%

Related for WPVDB-ID:9965AA9E-359E-4D9F-86C4-1CAEA1594799