What the vulnerability does
01Description
Missing Authorization vulnerability in Saleswonder Team: Tobias 5 Stars Rating Funnel 5-stars-rating-funnel.This issue affects 5 Stars Rating Funnel: from n/a through <= 1.2.67.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
What the vulnerability does
Missing Authorization vulnerability in Saleswonder Team: Tobias 5 Stars Rating Funnel 5-stars-rating-funnel.This issue affects 5 Stars Rating Funnel: from n/a through <= 1.2.67.
Explanation of Vulnerability in Simple Terms
The 5 Stars Rating Funnel plugin fails to properly check user permissions before allowing access to sensitive functions. An attacker without authentication can disrupt the site's availability by sending network requests that consume resources or crash the service. All versions up to 1.2.67 are affected. Update to a version newer than 1.2.67 to resolve this issue.
What an attacker can do
Disrupt site availability by making unauthenticated requests that exhaust resources or cause the service to become unavailable.
Potential impact on your site
Your site may become slow or unresponsive due to resource exhaustion attacks targeting the unprotected plugin functions.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities