Minimist <= 1.2.5 - Prototype Pollution
criticalMinimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95). Fixed in 1.2.6. Some WordPress plugins and themes use this dependency though that doesn’t necessarily mean the plugin itself is vulnerable to exploitation.
- CVSS:
- 9.8
- Affected:
- up to 1.2.0
- Fixed in:
- 1.2.1
- Disclosed:
- Mar 18, 2022