Lucene search

K
wpvulndbWpvulndbWPVDB-ID:DFC80C97-5AED-46A5-80ED-1864555C4E76
HistoryJan 03, 2024 - 12:00 a.m.

WC Marketplace < 4.0.24 - Missing Authorization via mvx_save_dashpages

2024-01-0300:00:00
wpscan.com
5
wordpress
vulnerability
missing capability check
plugin settings
unauthenticated attackers

7 High

AI Score

Confidence

Low

0 Low

EPSS

Percentile

0.0%

Description The WC Marketplace plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the β€˜mvx_save_dashpages’ function in versions up to, and including, 4.0.23. This makes it possible for unauthenticated attackers to update the plugin’s settings.

CPENameOperatorVersion
eq4.0.24

7 High

AI Score

Confidence

Low

0 Low

EPSS

Percentile

0.0%

Related for WPVDB-ID:DFC80C97-5AED-46A5-80ED-1864555C4E76