PT-2026-60705 · WordPress · Fense Proxy & Vpn Blocker
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Fense Proxy & VPN Blocker versions prior to 3.0.2
Description
Unauthorized modification of data is possible due to a missing capability check and missing nonce validation in the
fense bpvt save settings() function. The callback is registered to both wp ajax * and wp ajax nopriv * hooks and unconditionally calls delete option() on four plugin options and delete transient() on three transients related to the plugin's API key cache and settings. This allows unauthenticated attackers to delete plugin options and transients, resetting the API key and data cache, which forces the plugin to refetch state.Recommendations
Update to a version newer than 3.0.1.
As a temporary mitigation, restrict access to the
fense bpvt save settings() function.Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fense Proxy & Vpn Blocker