What the vulnerability does
01Description
Missing Authorization vulnerability in RabbitLoader.This issue affects RabbitLoader: from n/a through 2.19.13.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in RabbitLoader.This issue affects RabbitLoader: from n/a through 2.19.13.
Explanation of Vulnerability in Simple Terms
RabbitLoader versions up to 2.19.13 lack proper authorization checks, allowing authenticated users to modify site data without appropriate permissions. An attacker with low-level access can alter content or settings they should not be able to change. The vulnerability requires valid login credentials but no special privileges.
What an attacker can do
Modify or delete site data and settings beyond their assigned permissions.
Potential impact on your site
Unauthorized changes to site content, settings, or functionality by compromised or malicious user accounts.
Conditions required to exploit
Valid login credentials with low-level user role (e.g., subscriber or contributor).
Key dates
External resources
Related vulnerabilities