Blockbooster <= 1.0.10 - Missing Authorization
mediumThe Blockbooster theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the blockbooster_dismissble_notice() and blockbooster_install_and_activate_plugins() functions in versions up to, and including, 1.0.10. This makes it possible for unauthenticated attackers to di...
- CVSS:
- 5.3
- Affected:
- up to 1.0.10
- Fixed in:
- 1.0.11
- Disclosed:
- Aug 28, 2024