WordPress Plugin Vulnerabilities

Temporary Login Without Password < 1.7.1 - Subscriber+ Plugin's Settings Update

Description

The plugin does not have authorisation and CSRF checks when updating its settings, which could allows any logged-in users, such as subscribers to update them

Proof of Concept

Affects Plugins

References

Classification

Type
INCORRECT AUTHORISATION
CWE

Miscellaneous

Original Researcher
apple502j
Submitter
apple502j
Verified
Yes

Timeline

Publicly Published
2021-11-15 (about 4 years ago)
Added
2021-11-15 (about 4 years ago)
Last Updated
2022-04-09 (about 3 years ago)

Other