Description


The EmbedPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'admin_post_remove' and 'remove_private_data' functions in versions up to, and including, 3.8.2. This makes it possible for authenticated attackers with subscriber privileges or above, to delete plugin settings.

Weaknesses



CWE-862

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

5.4 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2023-08-10T10:15:12.000Z

2 years ago

Last modified

2024-11-21T07:34:47.123Z

1 year ago