WordPress Leads < 1.6.3 - Authorization Bypass
medium
The WordPress Leads plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on multiple functions in versions up to, and including, 1.6.2. This makes it possible for unathenticated attackers to include malicious content in Leads, which may be executed upon viewing in the dashboard a...
- CVSS:
- 5.3
- Affected:
- up to 1.6.3
- Fixed in:
- 1.6.3
- Disclosed:
- Mar 31, 2015
WordPress Leads [leads] < 1.6.3 (closed)
unknown
Because of this vulnerability, attackers can include arbitrary content, such as HTML or Java Script.
Upgrade this plugin.
- Affected:
- up to 1.6.3
- Fixed in:
- 1.6.3
- Disclosed:
- Mar 31, 2015
WordPress Leads [leads] < 1.6.3
unknown
The WordPress Leads plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on multiple functions in versions up to, and including, 1.6.2. This makes it possible for unathenticated attackers to include malicious content in Leads, which may be executed upon viewing in the dashboard a...
- Affected:
- up to 1.6.3
- Fixed in:
- 1.6.3
- Disclosed:
- Mar 31, 2015
WordPress Leads [leads] >= 1.6.1 - <= 1.6.2 (closed)
unknown
The WordPress Leads plugin exposes a number of functions via AJAX to Anonymous users via the ‘nopriv_’ prefix. One of these functions that is registered in ‘leads/shared/classes/class.lead-storage.php’ controls the insertion of leads into the database.
A number of fields accepted as POST para...
- Affected:
- 1.6.1 – 1.6.2
- Fixed in:
- 1.6.2
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database