What the vulnerability does
01Description
Missing Authorization vulnerability in Cool Plugins Cryptocurrency Widgets – Price Ticker & Coins List.This issue affects Cryptocurrency Widgets – Price Ticker & Coins List: from n/a through 2.6.8.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in Cool Plugins Cryptocurrency Widgets – Price Ticker & Coins List.This issue affects Cryptocurrency Widgets – Price Ticker & Coins List: from n/a through 2.6.8.
Explanation of Vulnerability in Simple Terms
Cryptocurrency Widgets – Price Ticker & Coins List through version 2.6.8 contains an authorization flaw that allows high-privilege users to read, modify, or delete limited data without proper permission checks. The vulnerability requires administrator-level access and does not affect site availability. A patch version has not been publicly identified.
What an attacker can do
Read, modify, or delete data if they have administrator access to the site.
Potential impact on your site
Administrators with malicious intent or compromised admin accounts can access or alter plugin data beyond their intended scope.
Conditions required to exploit
Attacker must have administrator-level privileges on the WordPress site.
Key dates
External resources
Related vulnerabilities