The invite-anyone plugin before 1.3.16 for WordPress has incorrect access control for email-based invitations.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://wordpress.org/plugins/invite-anyone/#developers | issue tracking third party advisory |