PT-2023-12485 · WordPress · Wordpress Automatic Plugin
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WordPress Automatic Plugin versions up to, and including, 3.53.2
Description
The issue is caused by missing authorization and option validation in the process form.php file, allowing unauthenticated attackers to update site settings and potentially compromise the site.
Recommendations
For versions up to, and including, 3.53.2, update to a version that includes the necessary authorization and validation fixes to prevent arbitrary options updates.
Exploit
Correção
Missing Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Wordpress Automatic Plugin