VulnerabilityModified
CVE-2020-14205
The DiveBook plugin 1.1.4 for WordPress is prone to improper access control in the Log Dive form because it fails to perform authorization checks.
MEDIUM 5.3EPSS 1.15%
Does this matter?
Lower severity and a low EPSS score (1.15%). Track it; it rarely justifies an emergency change on its own.
Description
The DiveBook plugin 1.1.4 for WordPress is prone to improper access control in the Log Dive form because it fails to perform authorization checks. An attacker may leverage this issue to manipulate the integrity of dive logs.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 1.15% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-862
- Affected
- divebook project/divebook
- Source
- cve@mitre.org
References
- https://wordpress.org/plugins/divebook/#developersRelease Notes, Vendor Advisory
- https://www.hooperlabs.xyz/disclosures/divebook.phpExploit, Third Party Advisory
- https://wordpress.org/plugins/divebook/#developersRelease Notes, Vendor Advisory
- https://www.hooperlabs.xyz/disclosures/divebook.phpExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.