What the vulnerability does
01Description
Missing Authorization vulnerability in billingo Official Integration for Billingo billingo allows Privilege Escalation.This issue affects Official Integration for Billingo: from n/a through <= 4.3.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Missing Authorization vulnerability in billingo Official Integration for Billingo billingo allows Privilege Escalation.This issue affects Official Integration for Billingo: from n/a through <= 4.3.0.
Explanation of Vulnerability in Simple Terms
The Official Integration for Billingo plugin through version 4.3.0 lacks proper authorization checks on sensitive operations. An authenticated administrator can read, modify, or delete data without proper permission validation. This affects confidentiality, integrity, and availability of site data. Update to a version newer than 4.3.0.
What an attacker can do
Read, modify, or delete sensitive data if authenticated as an administrator.
Potential impact on your site
Administrators could abuse their access to compromise billing data, customer information, or site integrity.
Conditions required to exploit
Attacker must have administrator-level access to the WordPress site.
Key dates
External resources
Related vulnerabilities