MainWP White Label Extension <= 4.1.1 - Missing Authorization to Plugin Settings Change
mediumThe MainWP White Label Extension plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 4.1.1 due to a missing capability check. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change the plugin's settings.
- CVSS:
- 6.4
- Affected:
- up to 4.1.1
- Fixed in:
- 4.1.2
- Disclosed:
- Jan 17, 2023