Weblizar Pin It Button On Image Hover And Post, e3eb806cbcd2fc7656b61a5bba70b0aebb0f9307
- CVE, Research URL
- Application
- Published on
- Apr 04, 2022
- Research Description
- Weblizar Pin It Button On Image Hover And Post [pinterest-pin-it-button-on-image-hover-and-post] < 3.4 Weblizar Pin It Button On Image Hover And Post < 3.4 - Authorization Bypass The Weblizar Pin It Button On Image Hover And Post plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the 'SaveSettings' function in versions up to, and including, 3.3. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change plugin settings.
- Affected versions
-
max 3.4.
- Status
-
vulnerable