What the vulnerability does
01Description
Missing Authorization vulnerability in Themify Post Type Builder (PTB).This issue affects Post Type Builder (PTB): from n/a through 2.0.8.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
What the vulnerability does
Missing Authorization vulnerability in Themify Post Type Builder (PTB).This issue affects Post Type Builder (PTB): from n/a through 2.0.8.
Explanation of Vulnerability in Simple Terms
Post Type Builder through version 2.0.8 lacks proper authorization checks, allowing authenticated users with low privileges to modify site content and settings they should not access. An attacker with a basic user account can change post types, custom fields, and other structural elements. This affects the integrity of site data and could allow privilege escalation or content manipulation.
What an attacker can do
Modify post types, custom fields, and site structure without proper permission checks.
Potential impact on your site
Unauthorized users can alter your site's post structure and custom fields, risking data corruption and content tampering.
Conditions required to exploit
Attacker must have a low-privilege user account (e.g., Contributor or Subscriber role).
Key dates
External resources
Related vulnerabilities