Lucene search

K
wpvulndbWpvulndbWPVDB-ID:0DC5F6FA-AB89-4C16-87CB-0BF9F548D3EF
HistoryNov 23, 2023 - 12:00 a.m.

Pre-Publish Checklist < 1.1.2 - Insecure Direct Object Reference to Arbitrary Post '_ppc_meta_key' Update

2023-11-2300:00:00
wpscan.com
25
wordpress
vulnerability
insecure direct object reference
pre-publish checklist

AI Score

6.9

Confidence

High

EPSS

0.001

Percentile

20.0%

Description The Pre-Publish Checklist plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 1.1.1 via the ppc_meta_box_ajax_add_handler and ppc_meta_box_ajax_delete_handler functions due to missing validation on a user controlled key. This can allow authenticated attackers with contributor-level access and above to modify and delete the ‘_ppc_meta_key’ post meta value for arbitrary posts.

AI Score

6.9

Confidence

High

EPSS

0.001

Percentile

20.0%

Related for WPVDB-ID:0DC5F6FA-AB89-4C16-87CB-0BF9F548D3EF