Lucene search

K
wpvulndbWpvulndbWPVDB-ID:5116068F-4B84-42AD-A88D-03E46096B41C
HistoryJan 05, 2023 - 12:00 a.m.

Social Warfare < 4.3.1 - Subscriber+ Post Meta Deletion

2023-01-0500:00:00
wpscan.com
5
social warfare
security vulnerability
ajax actions
post meta
access tokens

0.001 Low

EPSS

Percentile

30.5%

The plugin does not have authorisation in some AJAX actions, allowing any authenticated users, such as subscriber, to call them and delete arbitrary post meta as well as reset access tokens related to network

CPENameOperatorVersion
social-warfarelt4.3.1

0.001 Low

EPSS

Percentile

30.5%

Related for WPVDB-ID:5116068F-4B84-42AD-A88D-03E46096B41C