WordPress Plugin Vulnerabilities

RestroPress < 2.8.3.1 - Unauthorised AJAX Calls

Description

The plugin did not check for CSRF as well as capability in some of its AJAX calls which should only be accessible by admin. As a result, any authenticated user can change arbitrary order status, as well as access arbitrary order details (including PII such as phone number and address)

Proof of Concept

Affects Plugins

Fixed in 2.8.3.1

Classification

Type
ACCESS CONTROLS
CWE
CVSS

Miscellaneous

Original Researcher
WPScanTeam
Verified
Yes

Timeline

Publicly Published
2021-07-19 (about 4 years ago)
Added
2021-07-19 (about 4 years ago)
Last Updated
2021-07-19 (about 4 years ago)

Other