Fiche vulnérabilité
CVE-2023-6029 : faille élevée spider-themes eazydocs (CVSS 7.5)
Description
The EazyDocs WordPress plugin before 2.3.6 does not have authorization and CSRF checks when handling documents and does not ensure that they are documents from the plugin, allowing unauthenticated users to delete arbitrary posts, as well as add and delete documents/sections.
En bref
- Sévérité
- Élevée (CVSS 7.5)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Exploitation active
- Non signalée par la CISA
- Publication
- 15 janv. 2024
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- spider-themes eazydocs