What the vulnerability does
01Description
Missing Authorization vulnerability in Martin Gibson WP GoToWebinar.This issue affects WP GoToWebinar: from n/a through 14.46.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
What the vulnerability does
Missing Authorization vulnerability in Martin Gibson WP GoToWebinar.This issue affects WP GoToWebinar: from n/a through 14.46.
Explanation of Vulnerability in Simple Terms
WP GoToWebinar versions 14.46 and earlier lack proper authorization checks, allowing authenticated users with low privileges to trigger a denial-of-service condition. An attacker with a valid account can make requests that degrade site availability. The vulnerability requires an active user account but no special interaction from victims.
What an attacker can do
An authenticated user can degrade site availability by making unauthorized requests.
Potential impact on your site
Site availability may be impacted by authenticated users making unauthorized requests.
Conditions required to exploit
Attacker must have a valid low-privilege account on the site.
Key dates
External resources
Related vulnerabilities