What the vulnerability does
01Description
Missing Authorization vulnerability in Bill Minozzi WP Tools.This issue affects WP Tools: from n/a through 3.41.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Missing Authorization vulnerability in Bill Minozzi WP Tools.This issue affects WP Tools: from n/a through 3.41.
Explanation of Vulnerability in Simple Terms
WP Tools versions 3.41 and earlier lack proper authorization checks, allowing authenticated users with low privileges to read, modify, or delete sensitive data and functionality. An attacker with a basic user account can perform actions restricted to administrators. No user interaction is required once the attacker is logged in.
What an attacker can do
Read, modify, or delete data and settings restricted to administrators.
Potential impact on your site
Any registered user can access and modify admin-level settings and data.
Conditions required to exploit
Attacker must have a low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities