What the vulnerability does
01Description
Missing Authorization vulnerability in GenialSouls WP Social Comments.This issue affects WP Social Comments: from n/a through 1.7.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in GenialSouls WP Social Comments.This issue affects WP Social Comments: from n/a through 1.7.3.
Explanation of Vulnerability in Simple Terms
WP Social Comments versions up to 1.7.3 lack proper authorization checks, allowing authenticated users to modify content they should not have access to. An attacker with a low-privilege account can alter data through the plugin's functions. The vulnerability has a low integrity impact and requires valid site credentials to exploit.
What an attacker can do
Modify content or data they should not have permission to change.
Potential impact on your site
Authenticated users with limited roles can alter plugin data or settings beyond their intended permissions.
Conditions required to exploit
Attacker must have a low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities