WP SEO TDK <= 2.1.2 - Missing Authorization to Stored Cross-Site Scripting
highThe WP SEO TDK plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the seo-update AJAX action in versions up to, and including, 2.1.2. This makes it possible for unauthenticated attackers to modify the plugins setting and inject malicious web scripts that will execute wheneve...
- CVSS:
- 7.3
- Affected:
- up to 2.1.2
- Fix:
- No patched version reported
- Disclosed:
- Jul 20, 2021