What the vulnerability does
01Description
Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Preloader for Website.This issue affects Preloader for Website: from n/a through 1.2.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Preloader for Website.This issue affects Preloader for Website: from n/a through 1.2.2.
Explanation of Vulnerability in Simple Terms
The Preloader for Website plugin for WordPress contains a missing authorization check that allows unauthenticated attackers to modify site content. An attacker can send a network request to alter data without needing to log in or interact with a user. This affects versions up to 1.2.2. Site administrators should update to a version newer than 1.2.2 as soon as possible.
What an attacker can do
Modify site content or settings without logging in.
Potential impact on your site
Attackers can alter your site's content, preloader settings, or other data remotely without credentials.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities