SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-14205

The DiveBook plugin 1.1.4 for WordPress is prone to improper access control in the Log Dive form because it fails to perform authorization checks.

MEDIUM 5.3EPSS 1.15%

Does this matter?

Lower severity and a low EPSS score (1.15%). Track it; it rarely justifies an emergency change on its own.

Description

The DiveBook plugin 1.1.4 for WordPress is prone to improper access control in the Log Dive form because it fails to perform authorization checks. An attacker may leverage this issue to manipulate the integrity of dive logs.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS
1.15% probability · 65th percentile
CISA KEV
Not listed
Weakness
CWE-862
Affected
divebook project/divebook
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.