PT-2020-13931 · WordPress · Divebook Plugin

Published

2020-12-08

·

Updated

2020-12-10

·

CVE-2020-14205

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions DiveBook plugin version 1.1.4
Description The issue is related to improper access control in the Log Dive form of the DiveBook plugin for WordPress. It fails to perform authorization checks, which can be exploited by an attacker to manipulate the integrity of dive logs.
Recommendations For version 1.1.4, consider disabling access to the Log Dive form until a patch is available to prevent unauthorized manipulation of dive logs.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-14205

Affected Products

Divebook Plugin