What the vulnerability does
01Description
Missing Authorization vulnerability in Themeum WP Crowdfunding allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Crowdfunding: from n/a through 2.1.10.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in Themeum WP Crowdfunding allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Crowdfunding: from n/a through 2.1.10.
Explanation of Vulnerability in Simple Terms
WP Crowdfunding through version 2.1.10 lacks proper authorization checks, allowing authenticated users with low privileges to modify or disable functionality affecting other users or the site. The vulnerability has a changed scope, meaning impacts may extend beyond the vulnerable component itself. Authentication is required, but no special user interaction is needed.
What an attacker can do
Modify or disable site functionality that affects other users or the platform.
Potential impact on your site
Authenticated users can alter or disable features, potentially disrupting crowdfunding campaigns or site operations.
Conditions required to exploit
Attacker must have a low-privilege authenticated account on the WordPress site.
Key dates
External resources
Related vulnerabilities