BeRocket Plugins <= (Various Versions) - Missing Authorization
mediumSeveral BeRocket Plugins for WordPress are vulnerable to authorization bypass due to missing capability checks on functions corresponding to AJAX actions that are available to subscribers. This includes the close_notice, subscribe, disable_rate_notice, feature_request_send, get_plugin_error_ajax, close_notice, and test...
- CVSS:
- 5.4
- Affected:
- up to 3.5.7.6
- Fixed in:
- 3.5.7.7
- Disclosed:
- Dec 13, 2022