What the vulnerability does
01Description
Missing Authorization vulnerability in Loopus WP Cost Estimation & Payment Forms Builder.This issue affects WP Cost Estimation & Payment Forms Builder: from n/a through 10.1.76.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in Loopus WP Cost Estimation & Payment Forms Builder.This issue affects WP Cost Estimation & Payment Forms Builder: from n/a through 10.1.76.
Explanation of Vulnerability in Simple Terms
WP Cost Estimation & Payment Forms Builder through version 10.1.76 lacks proper authorization checks, allowing unauthenticated attackers to modify data and disrupt site functionality. The vulnerability requires no user interaction and can be exploited remotely. Site administrators should update to a version newer than 10.1.76 immediately.
What an attacker can do
Modify form data and disrupt site operations without logging in.
Potential impact on your site
Attackers can alter cost estimates, payment forms, and site data without credentials.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities