THE Leads Management System: 59sec LITE <= 3.4.1 - Authorization Bypass
mediumThe THE Leads Management System: 59sec LITE plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on an unknown function in versions up to, and including, 3.4.1. This makes it possible for unauthenticated attackers to update plugin settings.
- CVSS:
- 5.3
- Affected:
- up to 3.4.1
- Fix:
- No patched version reported
- Disclosed:
- Aug 12, 2022