What the vulnerability does
01Description
Auth. (author+) Broken Access Control vulnerability leading to Arbitrary File Deletion in Nabil Lemsieh Easy Media Replace plugin <= 0.1.3 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
What the vulnerability does
Auth. (author+) Broken Access Control vulnerability leading to Arbitrary File Deletion in Nabil Lemsieh Easy Media Replace plugin <= 0.1.3 versions.
Explanation of Vulnerability in Simple Terms
Easy Media Replace versions up to 0.1.3 lack proper authorization checks, allowing unauthenticated attackers to disrupt the site's availability. An attacker can send network requests without authentication to trigger a denial-of-service condition. The vulnerability affects multiple users and systems due to its changed scope. No user interaction is required.
What an attacker can do
Make the site unavailable or unresponsive by sending requests that consume resources or crash services.
Potential impact on your site
Your site may become slow or offline if targeted; users cannot access content or functionality.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities