What the vulnerability does
01Description
Missing Authorization vulnerability in codeSavory Knowledge Base documentation & wiki plugin – BasePress.This issue affects Knowledge Base documentation & wiki plugin – BasePress: from n/a through 2.16.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in codeSavory Knowledge Base documentation & wiki plugin – BasePress.This issue affects Knowledge Base documentation & wiki plugin – BasePress: from n/a through 2.16.1.
Explanation of Vulnerability in Simple Terms
BasePress versions up to 2.16.1 lack proper authorization checks, allowing authenticated users to modify or delete content they should not have access to. An attacker with a low-privilege account can change or remove documentation and wiki entries. The vulnerability requires a valid user login but no special interaction from victims.
What an attacker can do
Modify or delete knowledge base articles and wiki pages belonging to other users or restricted sections.
Potential impact on your site
Unauthorized users can corrupt, deface, or remove critical documentation and knowledge base content.
Conditions required to exploit
Attacker must have a valid user account with low-level permissions on the site.
Key dates
External resources
Related vulnerabilities