What the vulnerability does
01Description
Missing Authorization vulnerability in creativemotion Social Slider Feed allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Slider Feed: from n/a through 2.2.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in creativemotion Social Slider Feed allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Slider Feed: from n/a through 2.2.2.
Explanation of Vulnerability in Simple Terms
Social Slider Feed through version 2.2.2 fails to properly check user permissions before allowing access to certain functions. A logged-in user with low privileges can read data they should not have access to. The vulnerability does not allow data modification or system unavailability.
What an attacker can do
Read sensitive data they should not have access to as a low-privilege user.
Potential impact on your site
Unauthorized users can view restricted information, potentially exposing private content or user data.
Conditions required to exploit
Attacker must have a low-privilege account on the site and network access to the vulnerable plugin.
Key dates
External resources
Related vulnerabilities