WP Activity Log, 7e57cd4f4859826de00a8e2b09ee24fb7f2d824b
- CVE, Research URL
- Home page URL
- Application
- Published on
- Feb 25, 2019
- Research Description
- WP Activity Log [wp-security-audit-log] < 3.3.1.2 Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update The Freemius SDK for WordPress is vulnerable to authorization bypass due to a missing capability check on the _get_db_option and _set_db_option functions in versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change site settings and potentially take over the site.
- Affected versions
-
max 3.3.1.2.
- Status
-
vulnerable