WordPress Plugin Vulnerabilities
Featured Image from URL <= 2.7.7 - Missing Access Controls on REST routes
Description
The REST routes are missing permission callbacks, allowing unauthenticated/unauthorised users to call them.
Proof of Concept
Affects Plugins
References
Classification
Type
PRIVESC
OWASP top 10
CWE
Miscellaneous
Verified
No
WPVDB ID
Timeline
Publicly Published
2019-12-24 (about 6 years ago)
Added
2019-12-24 (about 6 years ago)
Last Updated
2019-12-24 (about 6 years ago)