HREFLANG Tags Lite <= 2.0.0 - Missing Authorization to Data Reset
mediumThe HREFLANG Tags Lite plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the hreflang_delete_all_data function called via a nopriv AJAX action in versions up to, and including, 2.0.0. This makes it possible for unauthenticated attackers to reset the plugin's data.
- CVSS:
- 5.3
- Affected:
- up to 2.0.0
- Fix:
- No patched version reported
- Disclosed:
- Sep 29, 2022