Lucene search

K
wpvulndbWpvulndbWPVDB-ID:B6CC2CC4-5629-4D11-A2A5-6181F620D2DE
HistoryNov 30, 2023 - 12:00 a.m.

Participants Database < 2.5.6 - Missing Authorization

2023-11-3000:00:00
wpscan.com
4
wordpress
vulnerability
data manipulation

7 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

24.3%

Description The Participants Database plugin for WordPress is vulnerable to unauthorized manipulation of data due to a missing capability check on several functions hooked via admin-post in all versions up to, and including, 2.5.5. This makes it possible for unauthenticated attackers to add and modify record fields.

CPENameOperatorVersion
eq2.5.6

7 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

24.3%

Related for WPVDB-ID:B6CC2CC4-5629-4D11-A2A5-6181F620D2DE