Lucene search

K
wpvulndbWpvulndbWPVDB-ID:B7B476F5-6463-47BA-9584-18EED3D7DBB5
HistoryNov 08, 2022 - 12:00 a.m.

Blog2Social < 6.9.12 - Subscriber+ Settings Update

2022-11-0800:00:00
wpscan.com
13
blog2social
plugin
update
unauthorized
user
settings

EPSS

0.001

Percentile

26.2%

The plugin does not have authorisation check when updating its settings, which could allow any authenticated users, such as subscriber to update them

EPSS

0.001

Percentile

26.2%

Related for WPVDB-ID:B7B476F5-6463-47BA-9584-18EED3D7DBB5