Embedder 1.3 - 1.3.5 - Authenticated (Subscriber+) Arbitrary Options Update
highThe Embedder plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the ajax_set_global_option() function in versions 1.3 to 1.3.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to u...
- CVSS:
- 8.8
- Affected:
- 1.3 – 1.3.5
- Fix:
- No patched version reported
- Disclosed:
- Apr 9, 2025