What the vulnerability does
01Description
Missing Authorization vulnerability in JS Morisset WPSSO Core wpsso allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPSSO Core: from n/a through <= 18.18.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in JS Morisset WPSSO Core wpsso allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPSSO Core: from n/a through <= 18.18.1.
Explanation of Vulnerability in Simple Terms
WPSSO Core contains an authorization flaw that allows authenticated users with low privileges to read sensitive information they should not access. The vulnerability affects all versions up to 18.18.1. An attacker with a basic user account can view data that is normally restricted to higher-privilege roles, potentially exposing private site information.
What an attacker can do
Read sensitive information restricted to higher-privilege users.
Potential impact on your site
Unauthorized users can access private or restricted data, risking exposure of site configuration or user information.
Conditions required to exploit
Attacker must have a low-privilege authenticated account on the site.
Key dates
External resources
Related vulnerabilities