WordPress Plugin Vulnerabilities

VikBooking < 1.6.8 - Insecure Direct Object References

Description

The plugin allows direct access to menus, allowing an authenticated user with subscriber privileges or above, to bypass authorization and access settings of the plugin's they shouldn't be allowed to.

Proof of Concept

Affects Plugins

Fixed in 1.6.8

References

Classification

Type
IDOR
CWE
CVSS

Miscellaneous

Submitter
cyc707
Verified
Yes

Timeline

Publicly Published
2024-04-19 (about 1 year ago)
Added
2024-04-19 (about 1 year ago)
Last Updated
2024-04-19 (about 1 year ago)

Other