What the vulnerability does
01Description
Missing Authorization vulnerability in 10up Simple Page Ordering allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Page Ordering: from n/a through 2.5.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in 10up Simple Page Ordering allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Page Ordering: from n/a through 2.5.0.
Explanation of Vulnerability in Simple Terms
Simple Page Ordering through version 2.5.0 does not properly check user permissions before allowing page reordering. An unauthenticated attacker can reorder pages on the site without logging in. This affects the integrity of page hierarchy and site structure. Update to a version newer than 2.5.0.
What an attacker can do
Reorder pages on the site without authentication.
Potential impact on your site
Unauthorized users can alter your page hierarchy and site structure without permission.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities