Lucene search

K
wpvulndbWpvulndbWPVDB-ID:D3AEB1E3-789A-4D3F-AE8E-B277CBC06056
HistoryNov 28, 2022 - 12:00 a.m.

WP Shamsi < 4.1.1 - Unauthenticated Arbitrary Plugin Deactivation

2022-11-2800:00:00
wpscan.com
12
wordpress
shamsi
vulnerability
unauthenticated
plugin deactivation

EPSS

0.001

Percentile

26.1%

The plugin does not have authorisation check when activating plugins via an action hooked to init(), which could allow unauthenticated attackers to deactivate arbitrary plugins from the blog

EPSS

0.001

Percentile

26.1%

Related for WPVDB-ID:D3AEB1E3-789A-4D3F-AE8E-B277CBC06056