WordPress Plugin Vulnerabilities
Catch Web Tools < 2.7.1 - Subscriber+ Arbitrary Catch IDs Activation/Deactivation
Description
The plugin does not have authorisation and CSRF check in its catchwebtools_catchids_switch AJAX action, allowing any authenticated users, such as subscriber to activate/disable Catch IDs
Proof of Concept
Affects Plugins
References
Classification
Type
NO AUTHORISATION
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Jan w Oleju
Submitter
Jan w Oleju
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2022-01-24 (about 4 years ago)
Added
2022-01-24 (about 4 years ago)
Last Updated
2022-01-24 (about 4 years ago)