Lucene search

K
wpvulndbWpvulndbWPVDB-ID:8E5B3E67-7640-48A0-B1E0-C118EB9DE8D8
HistoryAug 10, 2023 - 12:00 a.m.

EmbedPress < 3.8.3 - Subscriber+ Plugin Settings Delete

2023-08-1000:00:00
wpscan.com
2
plugin
authorize access
admin post remove
remove private data
low privileged users
subscribers
delete
settings

6.4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

20.0%

Description The plugin does not properly authorize access to its admin_post_remove and remove_private_data actions, allowing low privileged users (such as subscribers) to delete plugin settings.

CPENameOperatorVersion
eq3.8.3

6.4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

20.0%

Related for WPVDB-ID:8E5B3E67-7640-48A0-B1E0-C118EB9DE8D8