What the vulnerability does
01Description
Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions.
Explanation of Vulnerability in Simple Terms
Cyr to Lat reloaded through version 1.3.3 does not properly check user permissions before allowing certain actions. A logged-in user with low privileges can modify data they should not have access to. The vulnerability affects the plugin's core functionality and requires an active WordPress user account to exploit.
What an attacker can do
A low-privilege logged-in user can modify data they should not have permission to change.
Potential impact on your site
Unauthorized users can alter site content or settings through the plugin, potentially corrupting data or changing site behavior.
Conditions required to exploit
Attacker must have a valid WordPress user account with low-level permissions (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities