What the vulnerability does
01Description
Missing Authorization vulnerability in Sparkle WP Editorialmag editorialmag.This issue affects Editorialmag: from n/a through 1.1.9.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Sparkle WP Editorialmag editorialmag.This issue affects Editorialmag: from n/a through 1.1.9.
Explanation of Vulnerability in Simple Terms
Editorialmag through version 1.1.9 lacks proper authorization checks, allowing authenticated users to modify content they should not have access to. An attacker with a low-privilege account can alter data integrity without administrative approval. The vulnerability requires valid login credentials but no additional user interaction. Update to a version newer than 1.1.9 to remediate.
What an attacker can do
Modify content or settings without proper authorization as a low-privilege user.
Potential impact on your site
Unauthorized changes to site content or configuration by users with limited intended permissions.
Conditions required to exploit
Valid login account with low-level privileges; network access to the site.
Key dates
External resources
Related vulnerabilities