Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update
highThe Freemius SDK for WordPress is vulnerable to authorization bypass due to a missing capability check on the _get_db_option and _set_db_option functions in versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change site settings and...
- CVSS:
- 8.8
- Affected:
- up to 1.0.6
- Fix:
- No patched version reported
- Disclosed:
- Feb 25, 2019