Ultimate GDPR & CCPA <= 2.4 - Unauthenticated Settings Import & Export
highThe Ultimate GDPR & CCPA plugin for WordPress is vulnerable to unauthenticated settings import and export via the export_settings & import_settings functions in versions up to, and including, 2.4. This makes it possible for unauthenticated attackers to change plugin settings and conduct attacks such as redirecting visi...
- CVSS:
- 7.5
- Affected:
- up to 2.5
- Fixed in:
- 2.5
- Disclosed:
- Feb 5, 2021