PT-2025-45065 · WordPress · Features
CVSS v3.1
4.3
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Features plugin for WordPress versions up to and including 0.0.2
Description
The Features plugin for WordPress is susceptible to unauthorized data modification. This is due to a missing capability check on the
features revert option API endpoint. Authenticated attackers with Subscriber-level access or higher can revert options.Recommendations
Update the Features plugin to a version later than 0.0.2.
Correção
Missing Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Features