The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks capability checks for AJAX actions.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://www.wordfence.com/blog/2020/03/vulnerabilities-patched-in-the-data-tables-generator-by-supsystic-plugin/ | third party advisory exploit |