Member Directory and Contact Form <= 1.7.0 - Missing Authorization
mediumThe Member Directory and Contact Form plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pta_directory_save_order() function in versions up to, and including, 1.7.0. This makes it possible for authenticated attackers, with subscriber-level access and above,...
- CVSS:
- 4.3
- Affected:
- up to 1.7.0
- Fixed in:
- 1.8.0
- Disclosed:
- Dec 19, 2024