What the vulnerability does
01Description
Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform Defender Security defender-security.This issue affects Defender Security: from n/a through <= 4.7.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
What the vulnerability does
Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform Defender Security defender-security.This issue affects Defender Security: from n/a through <= 4.7.1.
Explanation of Vulnerability in Simple Terms
Defender Security for WordPress is missing authorization checks on certain administrative functions. An unauthenticated attacker can make requests to trigger a denial-of-service condition by exhausting site resources. The vulnerability affects all versions up to 4.7.1. Update to a version newer than 4.7.1 to resolve this issue.
What an attacker can do
Make unauthenticated requests to cause the site to become slow or unresponsive.
Potential impact on your site
Your site may experience downtime or performance degradation from unauthenticated denial-of-service attacks.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities