WordPress Plugin Vulnerabilities
Leyka < 3.31.2 - Missing Authorization
Description
The Leyka plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the sendCardCheck function in versions up to, and including, 3.31.1. This makes it possible for unauthenticated attackers to perform a card check.
Affects Plugins
References
Classification
Type
NO AUTHORISATION
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Mika
Verified
No
WPVDB ID
Timeline
Publicly Published
2024-06-06 (about 2 years ago)
Added
2024-06-12 (about 2 years ago)
Last Updated
2024-06-12 (about 2 years ago)