CVE-2018-11580
Mass Pages/Posts Creator <= 1.2.2 - Missing Authorization
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An issue was discovered in mass-pages-posts-creator.php in the MULTIDOTS Mass Pages/Posts Creator plugin 1.2.2 for WordPress. Any logged in user can launch Mass Pages/Posts creation with custom content. There is no nonce or user capability check, so anyone can launch a DoS attack against a site and create hundreds of thousands of posts with custom content.
Se ha descubierto un problema en mass-pages-posts-creator.php en el plugin MULTIDOTS Mass Pages/Posts Creator 1.2.2 para WordPress. Cualquier usuario que haya iniciado sesión puede iniciar la creación Mass Pages/Posts con contenido personalizado. No hay comprobaciones de nonce o de capacidades de usuario, por lo que cualquiera puede lanzar un ataque de denegación de servicio (DoS) contra un sitio y crear cientos de miles de publicaciones con contenido personalizado.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-05-30 CVE Reserved
- 2018-05-31 CVE Published
- 2024-09-16 CVE Updated
- 2024-09-16 First Exploit
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CWE-862: Missing Authorization
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://wordpress.org/plugins/mass-pagesposts-creator/#developers | Release Notes |
URL | Date | SRC |
---|---|---|
http://labs.threatpress.com/mass-pages-posts-creator | 2024-09-16 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Multidots Search vendor "Multidots" | Mass Pages\/posts Creator Search vendor "Multidots" for product "Mass Pages\/posts Creator" | 1.2.2 Search vendor "Multidots" for product "Mass Pages\/posts Creator" and version "1.2.2" | wordpress |
Affected
|