PT-2022-27365 · WordPress · Mega Addons

Marco Wotschka

·

Published

2022-12-14

·

Updated

2022-12-20

·

CVE-2022-4501

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions Mega Addons plugin for WordPress versions up to, and including, 4.2.7
Description The issue is related to authorization bypass due to a missing capability check on the vc saving data function. This allows authenticated attackers with subscriber-level permissions and above to update the plugin's settings.
Recommendations For Mega Addons plugin for WordPress versions up to, and including, 4.2.7, update to a version higher than 4.2.7 to resolve the issue. As a temporary workaround, consider restricting access to the vc saving data function to prevent unauthorized updates to the plugin's settings.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-4501

Affected Products

Mega Addons