What the vulnerability does
01Description
Broken Authentication vulnerability in JumpDEMAND Inc. ActiveDEMAND plugin <= 0.2.27 at WordPress allows unauthenticated post update/create/delete.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Broken Authentication vulnerability in JumpDEMAND Inc. ActiveDEMAND plugin <= 0.2.27 at WordPress allows unauthenticated post update/create/delete.
Explanation of Vulnerability in Simple Terms
ActiveDEMAND versions up to 0.2.27 contain an authentication flaw that allows attackers to modify data or disrupt service without valid credentials. The vulnerability requires only network access and no user interaction. Organizations running affected versions should upgrade to 0.2.47 or later to restore proper authentication controls.
What an attacker can do
Modify data or disrupt service without providing valid login credentials.
Potential impact on your site
Unauthorized users can alter or delete data and cause service interruptions without logging in.
Conditions required to exploit
Network access to the ActiveDEMAND instance; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities