What the vulnerability does
01Description
Authentication Bypass by Spoofing vulnerability in RafflePress Giveaways and Contests allows Functionality Bypass.This issue affects Giveaways and Contests: from n/a through 1.12.7.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Authentication Bypass by Spoofing vulnerability in RafflePress Giveaways and Contests allows Functionality Bypass.This issue affects Giveaways and Contests: from n/a through 1.12.7.
Explanation of Vulnerability in Simple Terms
RafflePress Giveaways and Contests versions up to 1.12.7 contain an authentication bypass vulnerability. An attacker can modify contest data or entries without proper authorization checks. The vulnerability requires network access but no user interaction or special privileges. Site administrators should update to a version newer than 1.12.7 to remediate the issue.
What an attacker can do
Modify contest data or entries without authorization.
Potential impact on your site
Giveaway and contest data can be altered by unauthorized users, compromising contest integrity.
Conditions required to exploit
Network access; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities