What the vulnerability does
01Description
Missing Authorization vulnerability in Mikado-Themes Wanderland wanderland allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wanderland: from n/a through <= 1.5.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Mikado-Themes Wanderland wanderland allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wanderland: from n/a through <= 1.5.
Explanation of Vulnerability in Simple Terms
Wanderland versions 1.5 and earlier contain an authorization bypass that allows authenticated users to modify content they should not have access to. The vulnerability stems from insufficient permission checks on certain operations. An attacker with a low-privilege account can alter data integrity without requiring user interaction. Update to a version newer than 1.5.
What an attacker can do
Modify content or settings they lack permission to change.
Potential impact on your site
Unauthorized users can alter site content, potentially defacing pages or corrupting data.
Conditions required to exploit
Attacker must have a low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities