Form Lightbox <= 2.1 - Unauthenticated Arbitrary Options Update
criticalThe Form Lightbox plugin for WordPress is vulnerable to arbitrary option updates due to a missing capability check in the /ajax.php file in versions up to, and including, 2.1. This makes it possible for unauthenticated attackers to edit arbitrary site options which can be used to create administrator accounts.
- CVSS:
- 9.8
- Affected:
- up to 2.1
- Fix:
- No patched version reported
- Disclosed:
- Jul 19, 2016