WordPress Plugin Vulnerabilities
Deeper Comments <= 2.1.1 - Subscriber+ Arbitrary Options Update
Description
The plugin does not have authorisation in its update_options AJAX action, allowing any authenticated users, such as subscribers to update arbitrary blog options (like default_role etc)
Affects Plugins
References
Classification
Type
NO AUTHORISATION
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Jerome Bruandet (Nintechnet)
Verified
No
WPVDB ID
Timeline
Publicly Published
2023-10-26 (about 2 years ago)
Added
2023-10-30 (about 2 years ago)
Last Updated
2023-12-26 (about 2 years ago)