WordPress HTTPS (SSL) <= 3.4.0 - Missing Authorization to Settings Change
highThe WordPress HTTPS (SSL) plugin is vulnerable to authenticated settings change in versions up to, and including, 3.4.0 due to using a nonce check in place of a capability check. This allows authenticated users with contributor permissions and above to modify the plugin settings, which can be used to configure the site...
- CVSS:
- 7.1
- Affected:
- up to 3.4.0
- Fix:
- No patched version reported
- Disclosed:
- Aug 6, 2022