WordPress Plugin Vulnerabilities
Qubely < 1.8.1 - Authenticated Arbitrary Settings Update
Description
The plugin does not have proper authorisation when saving its settings, allowing users with a role as low as subscriber (in versions < 1.7.9) or contributor (in v < 1.8.1) to update them
Proof of Concept
Affects Plugins
Classification
Type
NO AUTHORISATION
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Jan w Oleju
Submitter
Jan w Oleju
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2022-06-06 (about 3 years ago)
Added
2022-06-06 (about 3 years ago)
Last Updated
2022-06-14 (about 3 years ago)