What the vulnerability does
01Description
Missing Authorization vulnerability in Nico Martin Progressive WordPress (PWA).This issue affects Progressive WordPress (PWA): from n/a through 2.1.13.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in Nico Martin Progressive WordPress (PWA).This issue affects Progressive WordPress (PWA): from n/a through 2.1.13.
Explanation of Vulnerability in Simple Terms
Progressive WordPress (PWA) plugin versions up to 2.1.13 fail to properly check user permissions before allowing access to certain functions. A logged-in user with low privileges can read sensitive data they should not have access to. The vulnerability requires an active WordPress account but no special interaction from the victim.
What an attacker can do
Read sensitive data from the site that should be restricted to higher-privilege users.
Potential impact on your site
Unauthorized users can access confidential information; review who has accounts and consider auditing data access logs.
Conditions required to exploit
Attacker must have a low-privilege WordPress account (e.g., subscriber or contributor).
Key dates
External resources
Related vulnerabilities