PT-2026-3229 · WordPress · Getgenie
CVSS v3.1
4.3
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
GetGenie versions prior to 4.3.1
Description
The GetGenie plugin for WordPress has an authorization issue. The plugin does not correctly confirm a user’s permission to delete specific posts. This allows authenticated attackers with Author-level access or higher to delete any post on the WordPress site, even those created by other users.
Recommendations
Update GetGenie to version 4.3.1 or later.
Correção
Missing Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Getgenie