WordPress Plugin Vulnerabilities

WP Upload Restriction < 2.2.5 - Missing Access Control in getSelectedMimeTypesByRole

Description

Missing access control in getSelectedMimeTypesByRole function allows authenticated users, such as subscribers, to retrieve approved mime types for any given role.

Affects Plugins

References

Classification

Type
ACCESS CONTROLS
CWE

Miscellaneous

Verified
Yes

Timeline

Publicly Published
2021-07-07 (about 4 years ago)
Added
2021-07-07 (about 4 years ago)
Last Updated
2021-09-02 (about 4 years ago)

Other