PT-2023-16360 · WordPress · Contentstudio
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ContentStudio plugin for WordPress versions prior to 1.2.5
Description
The issue is related to authorization bypass due to a missing capability check on several functions. This allows unauthenticated attackers to obtain blog metadata, including the plugin's
contentstudio token, via the cstu get metadata function. Knowing this token enables other interactions with the plugin, such as creating posts.Recommendations
For versions prior to 1.2.5, update to version 1.2.5 or later, which adds other requirements to posting and updating, mitigating the risk of exploitation.
Exploit
Correção
Missing Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Contentstudio