WordPress Plugin Vulnerabilities

Qubely < 1.8.1 - Authenticated Arbitrary Settings Update

Description

The plugin does not have proper authorisation when saving its settings, allowing users with a role as low as subscriber (in versions < 1.7.9) or contributor (in v < 1.8.1) to update them

Proof of Concept

Affects Plugins

Fixed in 1.8.1

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Jan w Oleju
Submitter
Jan w Oleju
Verified
Yes

Timeline

Publicly Published
2022-06-06 (about 3 years ago)
Added
2022-06-06 (about 3 years ago)
Last Updated
2022-06-14 (about 3 years ago)

Other