What the vulnerability does
01Description
Missing Authorization vulnerability in AF themes WP Post Author.This issue affects WP Post Author: from n/a through 3.6.4.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in AF themes WP Post Author.This issue affects WP Post Author: from n/a through 3.6.4.
Explanation of Vulnerability in Simple Terms
WP Post Author through version 3.6.4 fails to properly check user permissions before allowing modifications to post authorship. A logged-in user with low privileges can change the author of posts without authorization. This affects the integrity of post attribution and audit trails on WordPress sites using this plugin.
What an attacker can do
Change the author of posts to another user account without permission.
Potential impact on your site
Post authorship can be altered by unauthorized users, compromising content attribution and audit integrity.
Conditions required to exploit
Attacker must have a low-privilege WordPress user account (e.g., subscriber or contributor).
Key dates
External resources
Related vulnerabilities