The plugin does not have proper authorisation and CSRF check in place when deleting publications, allowing any authenticated users, such as subscriber to delete arbitrary publication
The PoC will be displayed once the issue has been remediated
Muhammad Adel
Muhammad Adel
Yes
2021-12-28 (about 1 years ago)
2021-12-28 (about 1 years ago)
2022-04-16 (about 9 months ago)