What the vulnerability does
01Description
Authenticated (high role user) WordPress Options Change vulnerability in Biplob Adhikari's Tabs plugin <= 3.6.0 at WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Authenticated (high role user) WordPress Options Change vulnerability in Biplob Adhikari's Tabs plugin <= 3.6.0 at WordPress.
Explanation of Vulnerability in Simple Terms
The Tabs WordPress plugin version 3.6.0 and earlier contains an authorization flaw that allows authenticated administrators to read sensitive data, modify site content, or disrupt service. The vulnerability requires admin-level access and does not involve user interaction. Site owners should update to a version newer than 3.6.0 immediately.
What an attacker can do
Read sensitive data, modify content, or disrupt the site if they have admin access.
Potential impact on your site
An admin account compromise could expose data, alter site content, or cause downtime.
Conditions required to exploit
Attacker must have WordPress administrator privileges.
Key dates
External resources
Related vulnerabilities