What the vulnerability does
01Description
Missing Authorization vulnerability in Discourse WP Discourse.This issue affects WP Discourse: from n/a through 2.5.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in Discourse WP Discourse.This issue affects WP Discourse: from n/a through 2.5.1.
Explanation of Vulnerability in Simple Terms
WP Discourse versions up to 2.5.1 fail to properly check user permissions before allowing access to certain functions. A logged-in user with low privileges can read sensitive information that should be restricted to higher-privilege accounts. The vulnerability does not allow data modification or system unavailability.
What an attacker can do
Read sensitive data restricted to higher-privilege users.
Potential impact on your site
Unauthorized disclosure of private information to low-privilege users.
Conditions required to exploit
Attacker must have a low-privilege account on the site.
Key dates
External resources
Related vulnerabilities