WordPress Plugin Vulnerabilities

User Rights Access Manager < 1.0.8 - Access Restriction Bypass

Description

The plugin does not properly restrict access to pages, allowing admin users with restricted access (done by the plugin) to still access the related pages.

The issue is the same technique than https://blog.nintechnet.com/vulnerabilities-fixed-in-wordpress-controlled-admin-access-plugin/

Proof of Concept

Affects Plugins

Miscellaneous

Verified
Yes

Timeline

Publicly Published
2021-08-05 (about 4 years ago)
Added
2021-08-05 (about 4 years ago)
Last Updated
2022-01-05 (about 4 years ago)

Other