What the vulnerability does
01Description
Missing Authorization vulnerability in Saleswonder Team: Tobias WP2LEADS wp2leads.This issue affects WP2LEADS: from n/a through <= 3.2.7.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in Saleswonder Team: Tobias WP2LEADS wp2leads.This issue affects WP2LEADS: from n/a through <= 3.2.7.
Explanation of Vulnerability in Simple Terms
WP2LEADS versions 3.2.7 and earlier lack proper authorization checks, allowing authenticated users to modify or disable site functionality. An attacker with low-level access can alter settings or data without proper permission validation. Update to version 3.5.7 or later to resolve this issue.
What an attacker can do
Modify site settings or data without proper authorization as a low-privilege user.
Potential impact on your site
Unauthorized users can alter plugin settings or data, potentially disrupting site functionality or data integrity.
Conditions required to exploit
Attacker must have a valid user account with low-level privileges on the site.
Key dates
External resources
Related vulnerabilities