What the vulnerability does
01Description
Missing Authorization vulnerability in ThimPress Thim Core allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Thim Core: from n/a through 2.3.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in ThimPress Thim Core allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Thim Core: from n/a through 2.3.3.
Explanation of Vulnerability in Simple Terms
Thim Core through version 2.3.3 lacks proper authorization checks, allowing authenticated users to modify content they should not have access to. An attacker with low-level account privileges can change data integrity without requiring user interaction. The vulnerability affects the authorization layer of the plugin, enabling privilege escalation within the affected component.
What an attacker can do
Modify or alter data that should be restricted to higher-privilege users.
Potential impact on your site
Users with basic roles can bypass permission checks and alter protected content or settings.
Conditions required to exploit
Attacker must have a low-privilege authenticated account on the site.
Key dates
External resources
Related vulnerabilities