What the vulnerability does
01Description
Broken Access Control vulnerability in WordPress LoginPress plugin <= 1.6.2 on WordPress leading to unauth. changing of Opt-In or Opt-Out tracking settings.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Broken Access Control vulnerability in WordPress LoginPress plugin <= 1.6.2 on WordPress leading to unauth. changing of Opt-In or Opt-Out tracking settings.
Explanation of Vulnerability in Simple Terms
LoginPress versions up to 1.6.2 contain an integrity vulnerability that allows unauthenticated attackers to modify site data over the network without user interaction. The vulnerability stems from insufficient access controls on certain plugin functions. Site administrators should update to a version newer than 1.6.2 immediately.
What an attacker can do
Modify site data without authentication or user interaction.
Potential impact on your site
Attackers can alter site content, settings, or data without your knowledge or permission.
Conditions required to exploit
Network access only; no authentication or user action required.
Key dates
External resources
Related vulnerabilities