What the vulnerability does
01Description
Missing Authorization vulnerability in WP SCHEMA PRO Schema Pro.This issue affects Schema Pro: from n/a through 2.7.8.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in WP SCHEMA PRO Schema Pro.This issue affects Schema Pro: from n/a through 2.7.8.
Explanation of Vulnerability in Simple Terms
Schema Pro versions up to 2.7.8 lack proper authorization checks, allowing an attacker to read sensitive data by visiting a malicious link. The vulnerability requires user interaction—the victim must click a link or visit a page controlled by the attacker. No authentication is needed. The attacker gains access to confidential information but cannot modify or disable the site.
What an attacker can do
Read sensitive data from the site by tricking a user into visiting a malicious link.
Potential impact on your site
Confidential information may be exposed to attackers if users are tricked into clicking malicious links.
Conditions required to exploit
Victim must click an attacker-controlled link or visit a page the attacker directs them to.
Key dates
External resources
Related vulnerabilities