What the vulnerability does
01Description
Missing Authorization vulnerability in Kestrel WooCommerce AWeber Newsletter Subscription.This issue affects WooCommerce AWeber Newsletter Subscription: from n/a through 4.0.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in Kestrel WooCommerce AWeber Newsletter Subscription.This issue affects WooCommerce AWeber Newsletter Subscription: from n/a through 4.0.2.
Explanation of Vulnerability in Simple Terms
The WooCommerce AWeber Newsletter Subscription plugin through version 4.0.2 lacks proper authorization checks on certain functions. An unauthenticated attacker can modify data or disrupt service without needing to log in or interact with a site administrator. Update to a version newer than 4.0.2 to resolve this issue.
What an attacker can do
Modify plugin data or disrupt service without authentication.
Potential impact on your site
Unauthorized changes to newsletter settings or subscriber data; potential service disruption.
Conditions required to exploit
Network access to the site; no login or user interaction required.
Key dates
External resources
Related vulnerabilities