What the vulnerability does
01Description
Missing Authorization vulnerability in Theme4Press Demo Awesome allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Demo Awesome: from n/a through 1.0.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in Theme4Press Demo Awesome allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Demo Awesome: from n/a through 1.0.2.
Explanation of Vulnerability in Simple Terms
Demo Awesome through version 1.0.2 lacks proper authorization checks, allowing authenticated users with low privileges to modify site data without proper permission. An attacker can alter content or settings they should not have access to. The vulnerability requires a valid user account but no special interaction. Update to a version newer than 1.0.2.
What an attacker can do
Modify or delete site content and settings without proper authorization.
Potential impact on your site
Unauthorized users can alter your site's content, settings, or data integrity.
Conditions required to exploit
Valid user account with low privileges; network access to the site.
Key dates
External resources
Related vulnerabilities