WordPress Plugin Vulnerabilities

Leads-5050 Visitor Insights < 1.1.0 - Unauthorised License Change

Description

The leads5050_set_license AJAX action is available to authenticated users, but is missing any capability and CSRF checks. This could allow any low privilege users (subscriber+) to set an arbitrary license in the plugins settings

Proof of Concept

Affects Plugins

Classification

Type
ACCESS CONTROLS
CWE
CVSS

Miscellaneous

Original Researcher
WPScanTeam
Verified
Yes

Timeline

Publicly Published
2021-05-07 (about 4 years ago)
Added
2021-05-07 (about 4 years ago)
Last Updated
2021-05-07 (about 4 years ago)

Other