What the vulnerability does
01Description
Missing Authorization vulnerability in MVPThemes The League the-league allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The League: from n/a through <= 4.4.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
What the vulnerability does
Missing Authorization vulnerability in MVPThemes The League the-league allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The League: from n/a through <= 4.4.1.
Explanation of Vulnerability in Simple Terms
The League by MVPThemes versions 4.4.1 and earlier lack proper authorization checks, allowing authenticated users to disrupt site availability. An attacker with low-level account access can trigger a denial-of-service condition without requiring user interaction. Site administrators should update to a version newer than 4.4.1 to restore proper access controls.
What an attacker can do
An authenticated user can make the site unavailable or unresponsive to legitimate visitors.
Potential impact on your site
Your site may become unavailable or slow if a user account is compromised or misused.
Conditions required to exploit
Attacker must have a valid user account with low-level privileges on the site.
Key dates
External resources
Related vulnerabilities