What the vulnerability does
01Description
Unauthenticated plugin settings change vulnerability in 59sec THE Leads Management System: 59sec LITE plugin <= 3.4.1 at WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Unauthenticated plugin settings change vulnerability in 59sec THE Leads Management System: 59sec LITE plugin <= 3.4.1 at WordPress.
Explanation of Vulnerability in Simple Terms
The 59sec LITE WordPress plugin version 3.4.1 and earlier contains a flaw that allows unauthenticated attackers to modify data or disrupt service through the network. No special access or user interaction is required. Site administrators should update to a version newer than 3.4.1 to resolve this issue.
What an attacker can do
Modify plugin data or cause the site to become unavailable without needing to log in.
Potential impact on your site
Attackers can alter plugin settings or cause service disruption without any site credentials.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities