cleantalk
Vulnerabilities and Security Researches

Weblizar Pin It Button On Image Hover And Post, e3eb806cbcd2fc7656b61a5bba70b0aebb0f9307

Published on
Apr 04, 2022
Research Description
Weblizar Pin It Button On Image Hover And Post [pinterest-pin-it-button-on-image-hover-and-post] < 3.4 Weblizar Pin It Button On Image Hover And Post < 3.4 - Authorization Bypass The Weblizar Pin It Button On Image Hover And Post plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the 'SaveSettings' function in versions up to, and including, 3.3. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change plugin settings.
Affected versions
max 3.4.
Status
vulnerable