What the vulnerability does
01Description
Missing Authorization vulnerability in Wpmet WP Fundraising Donation and Crowdfunding Platform.This issue affects WP Fundraising Donation and Crowdfunding Platform: from n/a through 1.6.4.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in Wpmet WP Fundraising Donation and Crowdfunding Platform.This issue affects WP Fundraising Donation and Crowdfunding Platform: from n/a through 1.6.4.
Explanation of Vulnerability in Simple Terms
The WP Fundraising Donation and Crowdfunding Platform through version 1.6.4 does not properly check user permissions before allowing access to certain functions. An attacker without authentication can read sensitive information from the plugin. Update to a version newer than 1.6.4 to resolve this issue.
What an attacker can do
Read sensitive information from the plugin without logging in.
Potential impact on your site
Unauthorized users can access private fundraising or donation data exposed by the plugin.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities