WordPress · The Starbox – The Author Box For Humans · CVE-2024-0366
**Name of the Vulnerable Software and Affected Versions**
The Starbox – the Author Box for Humans plugin for WordPress versions up to, and including, 3.4.7
**Description**
The issue is related to Insecure Direct Object Reference, which allows subscribers to view plugin preferences and potentially other user settings due to missing validation on a user-controlled key in the action function.
**Recommendations**
For versions up to, and including, 3.4.7, update to a version later than 3.4.7 to resolve the issue.
As a temporary workaround, consider restricting access to the action function until a patch is available.