What the vulnerability does
01Description
Missing Authorization vulnerability in wpcreativeidea Advanced Testimonial Carousel for Elementor.This issue affects Advanced Testimonial Carousel for Elementor: from n/a through 3.0.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in wpcreativeidea Advanced Testimonial Carousel for Elementor.This issue affects Advanced Testimonial Carousel for Elementor: from n/a through 3.0.0.
Explanation of Vulnerability in Simple Terms
The Advanced Testimonial Carousel for Elementor plugin through version 3.0.0 lacks proper authorization checks on certain functions. A logged-in user with low privileges can modify testimonial data or settings they should not have access to. The vulnerability requires an active WordPress account but no special permissions. Site administrators should update the plugin to a version newer than 3.0.0.
What an attacker can do
Modify testimonial carousel data or settings without proper authorization.
Potential impact on your site
Unauthorized users can alter testimonial content, potentially defacing your site or injecting misleading information.
Conditions required to exploit
Attacker must have a low-privilege WordPress user account (e.g., subscriber or contributor).
Key dates
External resources
Related vulnerabilities