WP-DB-Table-Editor [wp-db-table-editor] <= 1.8.4 (unfixed + closed)
unknown
[en] The WP-DB-Table-Editor plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to lack of a default capability requirement on the 'dbte_render' function in all versions up to, and including, 1.8.4. This makes it possible for authenticated attackers, with contri...
- Affected:
- up to 1.8.4
- Fix:
- No patched version reported
- Disclosed:
- Jun 4, 2024
CVE-2024-2019 on NVD →
WP-DB-Table-Editor <= 1.8.4 - Missing Authorization to Authenticated(Contributor+) Database Access
high
The WP-DB-Table-Editor plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to lack of a default capability requirement on the 'dbte_render' function in all versions up to, and including, 1.8.4. This makes it possible for authenticated attackers, with contributor...
- CVSS:
- 7.5
- Affected:
- up to 1.8.4
- Fix:
- No patched version reported
- Disclosed:
- Jun 3, 2024
CVE-2024-2019 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database