Description The plugin is vulnerable to unauthorized modification of data due to a missing capability check on the insert_template function, allowing authenticated attackers, with subscriber-level access and above, to change page designs.
CPE | Name | Operator | Version |
---|---|---|---|
eq | 2.6.9 |