What the vulnerability does
01Description
Missing Authorization vulnerability in Aakash Chakravarthy Announcer – Notification & message bars.This issue affects Announcer – Notification & message bars: from n/a through 6.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Aakash Chakravarthy Announcer – Notification & message bars.This issue affects Announcer – Notification & message bars: from n/a through 6.0.
Explanation of Vulnerability in Simple Terms
The Announcer plugin for WordPress contains a missing authorization check that allows authenticated users with low privileges to modify notification and message bar content. An attacker with a basic user account can alter announcements without proper permission validation. This affects versions up to 6.0. Update to a version newer than 6.0 to resolve the issue.
What an attacker can do
Modify or alter notification and message bar content on the site without proper authorization.
Potential impact on your site
Unauthorized users can change site announcements and notifications, potentially spreading misinformation or defacing messaging.
Conditions required to exploit
Attacker must have a low-privilege WordPress user account (e.g., Subscriber or Contributor role).
Key dates
External resources
Related vulnerabilities