Lucene search

K
prionPRIOn knowledge basePRION:CVE-2020-36716
HistoryJun 07, 2023 - 2:15 a.m.

Authorization

2023-06-0702:15:00
PRIOn knowledge base
www.prio-n.com
2
wordpress
authorization bypass
capability check
unauthenticated attackers
setup wizard
configuration options

7 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

46.1%

The WP Activity Log plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the setup_page function in versions up to, and including, 4.0.1. This makes it possible for unauthenticated attackers to run the setup wizard (if it has not been run previously) and access plugin configuration options.

CPENameOperatorVersion
wp_activity_logle4.0.1

7 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

46.1%

Related for PRION:CVE-2020-36716