WordPress Plugin Vulnerabilities

InstaWP Connect < 0.0.9.19 - Unauthenticated Data Modification

Description

The plugin does not have authorisation check in its events_receiver function, allowing unauthenticated users to create/update/delete posts/taxonomy, install/activate/deactivate plugin, update the customizer settings as well as create/update/delete arbitrary users

Affects Plugins

Fixed in 0.0.9.19

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Lana Codes
Verified
No

Timeline

Publicly Published
2023-07-26 (about 2 years ago)
Added
2023-07-27 (about 2 years ago)
Last Updated
2023-07-27 (about 2 years ago)

Other