WordPress Plugin Vulnerabilities

Leads-5050 Visitor Insights < 1.0.4 - Unauthenticated License Change

Description

The leads5050_set_license AJAX action was available to unauthenticated users allowing them to set an arbitrary license in the plugins settings

Proof of Concept

Affects Plugins

References

Classification

Type
ACCESS CONTROLS
CWE
CVSS

Miscellaneous

Verified
Yes

Timeline

Publicly Published
2021-05-07 (about 4 years ago)
Added
2021-05-07 (about 4 years ago)
Last Updated
2021-05-07 (about 4 years ago)

Other