7.5
CVSSv3

CVE-2023-0331

Published: 27/02/2023 Updated: 07/11/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The Correos Oficial WordPress plugin up to and including 1.2.0.2 does not have an authorization check user input validation when generating a file path, allowing unauthenticated malicious users to download arbitrary files from the server.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

correos correos oficial