What the vulnerability does
01Description
Missing Authorization vulnerability in Mahesh Vora WP Page Post Widget Clone.This issue affects WP Page Post Widget Clone: from n/a through 1.0.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Mahesh Vora WP Page Post Widget Clone.This issue affects WP Page Post Widget Clone: from n/a through 1.0.1.
Explanation of Vulnerability in Simple Terms
WP Page Post Widget Clone versions up to 1.0.1 lack proper authorization checks, allowing authenticated users to read and modify data they should not have access to. An attacker with a low-privilege account can view or alter sensitive information without additional interaction. No availability impact occurs. Update to a version newer than 1.0.1.
What an attacker can do
Read and modify data belonging to other users or restricted areas of the site.
Potential impact on your site
Unauthorized users can access and alter sensitive site content, compromising data integrity and confidentiality.
Conditions required to exploit
Attacker must have a low-privilege WordPress account (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities