What the vulnerability does
01Description
Auth. (contributor+) Privilege Escalation vulnerability in Crowdsignal Dashboard plugin <= 3.0.9 on WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
What the vulnerability does
Auth. (contributor+) Privilege Escalation vulnerability in Crowdsignal Dashboard plugin <= 3.0.9 on WordPress.
Explanation of Vulnerability in Simple Terms
The Crowdsignal Dashboard plugin for WordPress contains an authorization flaw that allows authenticated users with low privileges to read, modify, or delete data they should not have access to. The vulnerability affects versions up to and including 3.0.9. An attacker with a basic WordPress user account can exploit this without user interaction to access or alter sensitive poll and survey information.
What an attacker can do
Read, modify, or delete polls and survey data belonging to other users or the site.
Potential impact on your site
Unauthorized users can access, alter, or destroy poll and survey data, compromising data integrity and user trust.
Conditions required to exploit
Attacker must have a low-privilege WordPress user account (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities