Vulnerabilities > Full

DATE CVE VULNERABILITY TITLE RISK
2023-08-09 CVE-2023-4242 Incorrect Authorization vulnerability in Full - Customer
The FULL - Customer plugin for WordPress is vulnerable to Information Disclosure via the /health REST route in versions up to, and including, 2.2.3 due to improper authorization.
network
low complexity
full CWE-863
4.3
2023-08-09 CVE-2023-4243 Unrestricted Upload of File with Dangerous Type vulnerability in Full - Customer
The FULL - Customer plugin for WordPress is vulnerable to Arbitrary File Upload via the /install-plugin REST route in versions up to, and including, 2.2.3 due to improper authorization.
network
low complexity
full CWE-434
8.8