What the vulnerability does
01Description
Missing Authorization vulnerability in WP Royal Ashe Extra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ashe Extra: from n/a through 1.2.9.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in WP Royal Ashe Extra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ashe Extra: from n/a through 1.2.9.
Explanation of Vulnerability in Simple Terms
Ashe Extra through version 1.2.9 lacks proper authorization checks, allowing authenticated users with low privileges to modify site content or disrupt service. An attacker with a basic user account can perform actions they should not be permitted to execute. The vulnerability affects integrity and availability but not confidentiality.
What an attacker can do
Modify site content or disrupt service availability with a low-privilege user account.
Potential impact on your site
Unauthorized users can alter content or cause downtime; requires immediate access review and update.
Conditions required to exploit
Attacker must have a valid low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities