Vulnerability in wordpress plugin DTracker v1.5, The code dtracker/save_contact.php doesn't check that the user is authorized before injecting new contacts into the wp_contact table.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/96890 | vdb entry third party advisory |
http://www.vapidlabs.com/advisory.php?v=186 | third party advisory exploit |
https://wordpress.org/plugins/dtracker/ | third party advisory |