Toret Manager <= 1.2.7 - Authenticated (Subscriber+) Arbitrary Options Update via AJAX actions
highThe Toret Manager plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'trman_save_option' function and on the 'trman_save_option_items' in all versions up to, and including, 1.2.7. This makes it possible for authenticated...
- CVSS:
- 8.8
- Affected:
- up to 1.2.7
- Fixed in:
- 1.3.0
- Disclosed:
- Feb 18, 2026