What the vulnerability does
01Description
Missing Authorization vulnerability in AF themes WP Post Author.This issue affects WP Post Author: from n/a through 3.6.4.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in AF themes WP Post Author.This issue affects WP Post Author: from n/a through 3.6.4.
Explanation of Vulnerability in Simple Terms
WP Post Author through version 3.6.4 fails to properly check user permissions before allowing modifications to post authorship. A logged-in user with low privileges can change the author of posts without authorization. The vulnerability requires an active WordPress account but no special access level.
What an attacker can do
Change the author of published posts to another user account.
Potential impact on your site
Post authorship can be altered by any logged-in user, potentially misattributing content or disrupting audit trails.
Conditions required to exploit
Attacker must have a valid WordPress user account with at least Subscriber-level access.
Key dates
External resources
Related vulnerabilities