What the vulnerability does
01Description
Missing Authorization vulnerability in AddonMaster Load More Anything.This issue affects Load More Anything: from n/a through 3.3.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in AddonMaster Load More Anything.This issue affects Load More Anything: from n/a through 3.3.3.
Explanation of Vulnerability in Simple Terms
Load More Anything versions 3.3.3 and earlier lack proper authorization checks, allowing authenticated users to modify or delete content they should not have access to. An attacker with a low-privilege account can alter site data or disrupt availability. Update to a version newer than 3.3.3.
What an attacker can do
Modify or delete content without proper permission checks.
Potential impact on your site
Unauthorized users can alter or remove site content, risking data loss and site integrity.
Conditions required to exploit
Attacker must have a low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities