Lucene search

K
wpvulndbWpvulndbWPVDB-ID:C3073685-856F-4473-9C9D-F8902A707F7A
HistoryNov 23, 2023 - 12:00 a.m.

MSHOP MY SITE <= 1.1.7 - Subscriber+ Settings Update

2023-11-2300:00:00
wpscan.com
4
plugin
unauthorized access
settings update
subscribers

8.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

24.1%

Description The plugin does not have authorisation check when updating its settings, which could allow any authenticated users, such as subscriber to update them

8.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

24.1%

Related for WPVDB-ID:C3073685-856F-4473-9C9D-F8902A707F7A