Lucene search

K
wpvulndbWpvulndbWPVDB-ID:26D308EF-D79E-4BB6-BD73-534710306B3A
HistoryJan 03, 2024 - 12:00 a.m.

Business Directory Plugin < 6.3.10 - Contributor+ Arbitrary Listing Deletion

2024-01-0300:00:00
wpscan.com
5
vulnerable
unauthorized access
data loss
contributor-level access

6.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Description The plugin is vulnerable to unauthorized loss of data due to a missing capability check on the ‘dispatch’ function, allowing authenticated attackers, with contributor-level access and above, to delete listings.

CPENameOperatorVersion
eq6.3.10

6.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Related for WPVDB-ID:26D308EF-D79E-4BB6-BD73-534710306B3A