What the vulnerability does
01Description
Missing Authorization vulnerability in RedLettuce Plugins WP Word Count allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Word Count: from n/a through 3.2.4.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in RedLettuce Plugins WP Word Count allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Word Count: from n/a through 3.2.4.
Explanation of Vulnerability in Simple Terms
WP Word Count contains an authorization flaw that allows authenticated users with low privileges to access sensitive information they should not see. The plugin fails to properly check user permissions before exposing data. An authenticated attacker can read information restricted to higher-privilege users. Update to a version newer than 3.2.4.
What an attacker can do
Read sensitive data restricted to higher-privilege users.
Potential impact on your site
Low-privilege users can access information meant only for admins or editors, risking data exposure.
Conditions required to exploit
Attacker must have a low-privilege WordPress account (e.g., subscriber or contributor).
Key dates
External resources
Related vulnerabilities