What the vulnerability does
01Description
Subscriber Broken Access Control in Push Notification for Post and BuddyPress <= 3.20 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
What the vulnerability does
Subscriber Broken Access Control in Push Notification for Post and BuddyPress <= 3.20 versions.
Explanation of Vulnerability in Simple Terms
The Push Notification for Post and BuddyPress plugin for WordPress does not properly check user permissions before allowing access to certain functions. A logged-in user with low privileges can read or modify data they should not have access to. Update to a version newer than 3.20.
What an attacker can do
A low-privilege logged-in user can read or modify data without proper authorization.
Potential impact on your site
Unauthorized users may access or alter notification settings, post data, or BuddyPress information.
Conditions required to exploit
Attacker must have a low-privilege account on the site (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities