What the vulnerability does
01Description
Missing Authorization vulnerability in Jerod Santo WordPress Console allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Console: from n/a through 0.3.9.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Jerod Santo WordPress Console allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Console: from n/a through 0.3.9.
Explanation of Vulnerability in Simple Terms
WordPress Console plugin versions up to 0.3.9 lack proper authorization checks on certain functions. An attacker without authentication can modify site data through network requests, though the attack requires specific conditions to succeed. Update to a version newer than 0.3.9 to resolve this issue.
What an attacker can do
Modify site data without logging in, under specific network conditions.
Potential impact on your site
Unauthorized changes to site content or settings if the plugin is active and unpatched.
Conditions required to exploit
Network access to the site; no authentication required, but attack complexity is high.
Key dates
External resources
Related vulnerabilities