ZeroHour

CVE-2023-0551

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p20
Published
()
Modified
Description

The REST API TO MiniProgram WordPress plugin through 4.6.1 does not have authorisation and CSRF checks in an AJAX action, allowing ay authenticated users, such as subscriber to call and delete arbitrary attachments

Vendors
minapper
Products
rest api to miniprogram
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

In the news

No ingested article mentions this CVE yet.