What the vulnerability does
01Description
Improper Privilege Management vulnerability in JR King/Eran Schoellhorn WP Masquerade allows Privilege Escalation.This issue affects WP Masquerade: from n/a through 1.1.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Improper Privilege Management vulnerability in JR King/Eran Schoellhorn WP Masquerade allows Privilege Escalation.This issue affects WP Masquerade: from n/a through 1.1.0.
Explanation of Vulnerability in Simple Terms
WP Masquerade versions up to 1.1.0 contain a privilege management flaw that allows authenticated users with low privileges to gain unauthorized access to sensitive data and modify site content. An attacker with a basic user account can read confidential information, alter posts or settings, and potentially disrupt site availability. No user interaction is required beyond initial authentication.
What an attacker can do
Read sensitive data, modify site content, and disrupt availability with a low-privilege user account.
Potential impact on your site
Compromised user accounts can access and modify protected content, risking data exposure and site integrity.
Conditions required to exploit
Attacker must have a valid low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities