What the vulnerability does
01Description
Missing Authorization vulnerability in Mark Winiarski WPLingo wplingo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPLingo: from n/a through <= 1.1.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
What the vulnerability does
Missing Authorization vulnerability in Mark Winiarski WPLingo wplingo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPLingo: from n/a through <= 1.1.2.
Explanation of Vulnerability in Simple Terms
WPLingo versions up to 1.1.2 lack proper authorization checks, allowing authenticated users with low privileges to disrupt site availability. An attacker with a basic user account can trigger a denial-of-service condition without requiring user interaction. The vulnerability affects the authorization logic that should restrict certain operations to higher-privilege roles.
What an attacker can do
Disrupt site availability by triggering a denial-of-service condition with a low-privilege user account.
Potential impact on your site
Site availability can be disrupted by any authenticated user, even those with minimal permissions.
Conditions required to exploit
Attacker must have a valid low-privilege user account on the site; no user interaction required.
Key dates
External resources
Related vulnerabilities