External Database Based Actions <= 0.1 - Authenticated (Subscriber+) Authentication Bypass
highThe External Database Based Actions plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 0.1. This is due to a missing capability check in the 'edba_admin_handle' function. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to update...
- CVSS:
- 7.5
- Affected:
- up to 0.1
- Fix:
- No patched version reported
- Disclosed:
- Nov 14, 2024