WordPress Plugin Vulnerabilities
Multilist Subscribe for Sendy <= 1.6.1 - Subscriber+ Arbitrary Options Update
Description
The plugin is using an outdated version of the Freemius library (1.2.2.9), which is known to be affected by a security issue allowing any authenticated users, such as subscriber to set arbitrary blog options
Proof of Concept
Affects Plugins
Classification
Type
PRIVESC
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
0xdecafbad
Submitter website
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2022-03-01 (about 4 years ago)
Added
2022-03-01 (about 4 years ago)
Last Updated
2022-03-01 (about 4 years ago)