What the vulnerability does
01Description
Auth. (subscriber+) Messaging Block Bypass vulnerability in Better Messages plugin <= 1.9.10.69 on WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Auth. (subscriber+) Messaging Block Bypass vulnerability in Better Messages plugin <= 1.9.10.69 on WordPress.
Explanation of Vulnerability in Simple Terms
The Better Messages WordPress plugin version 1.9.10.69 and earlier contains an authorization flaw that allows authenticated users to modify data they should not have access to. An attacker with a low-privilege account can alter information through the plugin's functionality. The vulnerability requires an active WordPress user account but no additional user interaction.
What an attacker can do
Modify data in the plugin that should be restricted to higher-privilege users.
Potential impact on your site
Unauthorized changes to plugin data by low-privilege users; integrity of messages or settings at risk.
Conditions required to exploit
Attacker must have a low-privilege WordPress user account (e.g., subscriber or contributor).
Key dates
External resources