PT-2025-29990 · WordPress · Aapanel Wp Toolkit
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
aapanel WP Toolkit versions 1.0 through 1.1
Description
The aapanel WP Toolkit plugin for WordPress is susceptible to privilege escalation due to missing authorization checks within the
auto login() function. Authenticated attackers with Subscriber-level access or higher can bypass role checks and obtain full admin privileges.Recommendations
Update aapanel WP Toolkit to a version newer than 1.1.
Correção
LPE
Missing Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Aapanel Wp Toolkit